Four Hacking Groups Share New Chrome and Windows Exploit Kit

Security firm Proofpoint reports that at least four hacking groups, some with ties to the Chinese government, are actively using a nearly identical exploit kit dubbed BlueMoon. The kit chains together three vulnerabilities—two affecting Chromium-based browsers and one affecting the Windows kernel—to install malware of the attacker's choice. Affected systems include Windows 10, Windows Server 2019 and 2022, and the initial release of Windows 11. Patches for all three flaws have shipped in the past 24 hours.

Unlike typical campaigns that use exploits sparingly to avoid detection, the attackers behind BlueMoon deploy it widely and openly. Proofpoint believes one driver is a "patch gap" in the Chromium supply chain, the window between when a fix is published upstream and when it reaches browsers like Chrome and Edge. Because Chromium is open source, attackers can reverse engineer publicly available patches before downstream products update, creating a brief but valuable opportunity.

AI likely plays a role as well, since it can discover vulnerabilities faster than human-only research. Proofpoint notes that a fully weaponized Chrome exploit chain has historically been rare and high-value, but BlueMoon was developed, deployed, and shared across multiple threat actors within days with high detection signals. The firm warns this reflects a falling cost and barrier to entry for advanced exploits as AI agents increasingly assist threat actors with exploit development.

Read More at the original source →