Four hacking groups caught using same Chrome and Windows exploit kit

By Central

Four distinct hacking groups, some with confirmed ties to the Chinese state, have been caught exploiting a nearly identical exploit kit that chains together critical vulnerabilities in Chromium-based browsers and older versions of Windows. Researchers at security firm Proofpoint disclosed on Wednesday that this kit, which they have named BlueMoon, represents a significant shift in the operational tempo and accessibility of high-end exploit development. The kit targets two vulnerabilities in the Chromium rendering engine and a third in the Windows kernel, affecting systems running Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 version 2004, Windows Server 2022, and the initial release of Windows 11. Patches for all three vulnerabilities were released within the last 24 hours, closing a window that the attackers exploited with unusual speed and visibility.

The BlueMoon Exploit Chain: A Trio of Critical Vulnerabilities

The BlueMoon exploit kit works by chaining three separate vulnerabilities together in a precise sequence. The first two exploits target flaws within the Chromium open-source codebase, which serves as the foundation for browsers like Google Chrome and Microsoft Edge. The third exploits a privilege escalation vulnerability within the Windows kernel. By chaining these exploits, an attacker can first gain a foothold within the browser sandbox, then escape that sandbox by compromising the kernel, ultimately gaining the high-level system access required to install arbitrary malware. This process is fully automated by the kit, meaning the attackers do not need to manually perform each step.

Proofpoint’s analysis indicates that the kit is nearly identical across all four observed threat actor groups. This uniformity suggests that the kit was developed by a single entity and then shared or sold to the others. The rapid dissemination of such a sophisticated capability is a notable departure from traditional cyber-espionage tradecraft, where exploit chains of this caliber are typically guarded as strategic assets and used sparingly to avoid burning the vulnerabilities.

What is the BlueMoon exploit kit and how does it work?

The BlueMoon exploit kit is a weaponized software package that automates the exploitation of three specific software vulnerabilities to install malware onto a victim’s computer. It works by first using a Chromium vulnerability to break out of the browser’s security sandbox, which normally isolates web content from the operating system. It then uses a second Chromium vulnerability, followed by a Windows kernel vulnerability, to escalate privileges to the highest system level (SYSTEM). Once this chain is complete, the attackers can execute arbitrary code, take full control of the machine, and deploy payloads such as backdoors, remote access tools, or data-stealing malware.

Four Threat Actors, One Shared Arsenal

Proofpoint identified four distinct hacking groups using the BlueMoon kit. The groups and their primary targets demonstrate a wide-ranging operational scope.

  • Group 1: Targeted organizations in the technology and telecommunications sectors, primarily in North America and Europe.
  • Group 2: Focused on government and diplomatic entities in Southeast Asia and Eastern Europe.
  • Group 3: Concentrated on defense contractors and aerospace firms in the United States and the United Kingdom.
  • Group 4: Targeted financial services and critical infrastructure operators in the Middle East and South Asia.

The diversity of targets—spanning continents, industries, and geopolitical alignments—suggests that BlueMoon was not developed for a single strategic objective. Instead, it was treated as a commoditized tool, available to any group that could acquire it. Some of these groups have historical links to Chinese state-sponsored cyber-espionage campaigns, according to Proofpoint’s threat intelligence. The fact that these groups, which normally operate independently, adopted the same kit within a very short timeframe indicates that the kit was either shared among a closed circle of affiliates or sold through underground markets.

Why the Attackers Chose Speed Over Stealth

The operational profile of the BlueMoon campaigns is notable for its lack of stealth. Traditional advanced persistent threat (APT) groups often go to great lengths to conceal their use of zero-day vulnerabilities. They might test the exploit in isolated environments, limit the number of targets, and carefully sequence their attacks to avoid detection by security products or incident response teams. The reasoning is simple: once a vulnerability is publicly known and exploited in the wild, vendors will rush to develop and release a patch, permanently eliminating the attacker’s advantage.

In the case of BlueMoon, the attackers did the opposite. They deployed the kit widely, across multiple groups, in a manner that generated high detection signals. Proofpoint hypothesized that this strategy was driven by two primary factors. First, the attackers sought to exploit what the researchers call a “patch gap” in the Chromium supply chain. This gap refers to the delay between the time the Chromium project releases a patch for a vulnerability and the time that patch is integrated into downstream browsers like Chrome and Edge. During this gap, the vulnerability is technically known to the software maintainers but remains unpatched in the browsers that most users actually run. The attackers appear to have reverse-engineered the patch itself—a technique known as patch diffing—to create their exploit before the patch reached end users.

Second, and more concerning, Proofpoint noted the likely role of artificial intelligence in accelerating the development of the exploit. AI agents are increasingly capable of analyzing open-source codebases, identifying vulnerable code patterns, and even generating exploit code. The open-source nature of Chromium makes it particularly susceptible to this kind of analysis. Because upstream patches are publicly visible before downstream consumers (like browser vendors) apply them, threat actors can use AI to rapidly reverse-engineer a fix and develop a working exploit. This lowers the cost and barrier to entry for creating what was once a rare and expensive capability: a full Chrome exploit chain.

How does the Chromium patch gap create a window for attackers?

The Chromium patch gap exists because the Chromium open-source project publishes its source code and patches publicly and immediately. When a security flaw is fixed in the upstream repository, anyone can view the patch and understand exactly which code changed. However, it typically takes days or weeks for that patch to be incorporated into stable releases of browsers like Google Chrome, Microsoft Edge, or Brave. During this interval, the vulnerability remains exploitable in the browsers that most people use. Attackers who can reverse-engineer the patch and develop an exploit during this window can target users who have not yet received the downstream update. This creates a predictable, recurring opportunity for rapid exploitation.

AI as an Accelerant for Exploit Development

The involvement of AI in the BlueMoon kit is a development with potentially far-reaching implications. Proofpoint’s report explicitly highlighted that AI agents increasingly enable threat actor exploit development, particularly for open-source codebases. The logic is straightforward: AI models can be trained to read source code, identify the specific code change in a patch, deduce the nature of the underlying vulnerability, and even generate exploit code that triggers it. This process can be automated to a degree that was previously impossible with human analysts alone.

The consequences are sobering. The historical rarity of fully weaponized Chrome exploit chains was a significant barrier for all but the most sophisticated state-sponsored groups. Developing such an exploit required deep expertise in browser internals, memory corruption, sandboxing, and kernel exploitation. That barrier is now eroding. If AI can reduce the time and skill required to turn a patch into a weapon, the supply of exploit kits like BlueMoon will increase. This democratization of advanced exploitation means that a wider range of threat actors—including those with fewer resources or less technical sophistication—could gain access to capabilities once reserved for elite APT groups.

Widespread Targeting and the Cost of Delayed Patching

The BlueMoon campaigns targeted a broad cross-section of organizations, demonstrating that no sector is immune. The targets included technology firms, government ministries, defense contractors, and financial institutions. This wide net suggests that the attackers were conducting opportunistic campaigns rather than highly selective operations. They cast a wide net, likely using spear-phishing emails, malvertising, or compromised websites to deliver the initial exploit to victims.

For enterprises and individual users, the takeaway is clear: the speed of patching is now more critical than ever. The gap between a patch’s release and its installation is the attacker’s window of opportunity. With AI shortening the time required to develop exploits, that window is shrinking. Organizations that delay applying patches—even by a few days—are increasingly likely to be compromised. The fact that the BlueMoon kit targeted both Chromium browsers and the Windows kernel means that patching must be coordinated across the entire software stack. A patched browser cannot protect a user if the underlying operating system remains vulnerable, and vice versa.

Technical Breakdown of the Three Vulnerabilities

While Proofpoint did not release the specific CVE identifiers for the three vulnerabilities in its public report, the company confirmed that all three were patched within the last 24 hours. The vulnerabilities fall into two categories:

  • Two Chromium vulnerabilities: These exist within the browser’s rendering engine, which processes HTML, JavaScript, and other web content. Successful exploitation of either flaw allows an attacker to execute code within the browser’s sandboxed environment, escaping the normal security restrictions that prevent web pages from accessing the operating system. One of these flaws likely involves a use-after-free or type confusion bug, which are common in browser exploits.
  • One Windows kernel vulnerability: This flaw resides in the core of the Windows operating system, the kernel. It allows an attacker who has already achieved code execution within the browser sandbox to elevate their privileges to the highest system level (SYSTEM). This gives them unrestricted access to the entire machine, including the ability to read, modify, or delete any file, install drivers, disable security software, and persist across reboots.

The chain is designed to be executed in sequence: the browser exploitation provides an initial foothold, and the kernel exploitation provides full control. Together, they bypass the two primary security layers on a modern Windows system: the browser sandbox and the operating system’s privilege model.

The Future of Exploit Development in an AI-Augmented Era

The BlueMoon kit may represent a watershed moment in the cybersecurity landscape. It is one of the first documented cases where a full Chrome exploit chain has been rapidly shared and deployed by multiple state-aligned groups. The involvement of AI in lowering the barrier to entry for such development adds a new dimension to the threat. Security professionals have long worried about the weaponization of AI for cyberattacks; BlueMoon provides concrete evidence that these concerns are being realized.

In the near term, defenders must adjust their strategies. Rapid patch management is no longer a best practice—it is an existential necessity. Organizations should consider using virtual patching, web application firewalls, and endpoint detection and response (EDR) tools that can detect exploit behavior even if the underlying vulnerability is unpatched. Browser isolation technologies, which render web content in a remote environment, can also neutralize exploits like BlueMoon by preventing any code from reaching the user’s local machine.

For the broader industry, the BlueMoon disclosure serves as a call to action. The open-source model, while immensely beneficial for innovation and transparency, introduces a structural vulnerability in the form of the patch gap. The Chromium project and downstream browser vendors may need to explore ways to reduce this gap, perhaps through staggered disclosure or faster integration of critical security fixes. Meanwhile, the security community must accelerate its own use of AI to detect and respond to threats, because the attackers are already using it.

Share This Article