4 hacking groups exploited same Chrome & Windows exploit kit

Original: 4 groups caught using the same Chrome and Windows exploit kit

Why This Matters

AI-accelerated exploit development and Chromium patch gaps are lowering barriers for state-linked threat actors.

Proofpoint revealed that at least 4 groups, including China-linked TA412, used the 'BlueMoon' exploit kit chaining 3 vulnerabilities in Chromium and Windows. Attacks began August 28 and targeted US NGOs, aerospace firms, and entities in Vietnam, Singapore, and Indonesia. All 3 vulnerabilities were patched within 24 hours of disclosure.

Security firm Proofpoint disclosed on September 9, 2026 that an exploit kit dubbed 'BlueMoon' was actively used by at least four distinct hacking groups, including state-sponsored actors with ties to China. The kit chains two Chromium V8 vulnerabilities with one Windows kernel vulnerability affecting Windows 10, Windows Server 2019, Windows Server 2022, and the initial Windows 11 release, enabling attackers to install malware of their choice. All three vulnerabilities received patches within 24 hours of the report.

The four identified groups and their targets were: TA412 (China-aligned, US-indicted in 2024), which hit US-based NGOs, mining companies, and commodity trading firms; UNK_LateNight (China-aligned espionage), which targeted multiple US aerospace companies; UNK_DoubleCheck, which targeted a Vietnamese manufacturing entity; and UNK_QuietRacket, which targeted organizations in Singapore and Indonesia. The first known attack began August 28 from TA412.

Proofpoint attributed the unusually rapid and broad sharing of the kit to two factors: a 'patch gap' in the Chromium supply chain (the delay between upstream patch release and downstream browser updates), and AI-assisted vulnerability discovery, which lowers the cost and time needed to reverse-engineer patches and develop working exploits. Proofpoint noted this may signal a reduced barrier to entry for weaponized browser exploit chains.

Source

arstechnica.com — Read original →