HeadlinesBriefing favicon HeadlinesBriefing.com

Four Hacking Groups Using Same Chrome and Windows Exploit Kit

Ars Technica •
×

Security firm Proofpoint has identified a nearly identical exploit kit, dubbed Blue Moon, actively used by at least four hacking groups, some with ties to the Chinese government. The kit chains three vulnerabilities—two in Chromium-based browsers and one in the Windows kernel affecting Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial Windows 11 release—to install malware. All three flaws received patches within the past 24 hours.

Unlike typical campaigns that use zero-days sparingly, Blue Moon was deployed rapidly and widely shared, lacking stealth. Proofpoint hypothesizes this visibility stems from a "patch gap" in the Chromium supply chain—the delay between upstream patch availability and downstream browser updates like Chrome and Edge. The firm also suggests AI accelerated vulnerability discovery and exploit development, lowering the barrier to entry for high-value capabilities.

Proofpoint noted that a fully weaponized Chrome exploit chain is historically rare, but Blue Moon was developed and shared across multiple threat actors within days. The four groups targeted a wide range of organizations, signaling a shift in how quickly sophisticated exploits can be commoditized and deployed.