Skip to content
News

BlueMoon Exploit Kit Hits Chrome and Windows Users

BlueMoon Exploit Kit Hits Chrome and Windows Users
The BlueMoon exploit kit chains Chrome and Windows flaws, used by four hacking groups with ties to China. All three vulnerabilities are now patched.

A newly identified BlueMoon exploit kit targeting critical vulnerabilities in Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some with ties to the Chinese government. Security researchers documented the kit and confirmed that all three vulnerabilities it relies upon received patches within the past 24 hours.

The kit chains three vulnerabilities together, enabling attackers to install malware of their choosing. It exploits two Chromium vulnerabilities alongside a flaw in the kernel of Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.

How the exploit chain works

Both browser vulnerabilities resided in V8, Google’s open source JavaScript engine. By exploiting a V8 type confusion bug and a separate sandbox escape, attackers were able to execute remote code. They then used a local privilege escalation flaw in older versions of Windows to run malicious code with elevated permissions.

Unusually, the attacks lacked the stealth typical of many campaigns. Hackers generally exploit newly discovered vulnerabilities sparingly to prolong their usefulness. Researchers suggested the widely visible chain aimed to exploit a patch gap in the Chromium supply chain, which spans the time between a fix being released by developers and its incorporation into browsers such as Chrome and Edge.

The use of AI was cited as another likely factor, as AI agents can often spot vulnerabilities faster than human-only discovery. A fully weaponised Chrome exploit chain has historically been a high-value, rare capability, yet BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days despite generating high detection signals. This may reflect a reduced cost and barrier to entry, particularly for open source codebases like Chromium, where upstream patches are publicly accessible before downstream consumers apply them.

Groups and targets identified

Four groups used the near-identical kit against a wide range of organisations. TA412, a China-aligned state-sponsored actor indicted by the US government in 2024 on behalf of China’s civilian foreign intelligence agency, repeatedly struck US organisations focused on non-governmental bodies, mining companies, and physical commodity trading firms.

UNKLateNight, a China-aligned espionage group, targeted multiple US aerospace companies. UNKDoubleCheck targeted a Vietnamese manufacturing entity, while UNK_QuietRacket activity focused on Singapore and Indonesia.

The first attack came from TA412 and began on 28 August, with the remaining campaigns starting earlier in the month. It remains unknown whether other groups also gained access to the exploit kit.

Source
Image: arstechnica.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals