Four hacking groups caught sharing the same BlueMoon exploit kit chaining Chrome and Windows flaws
Proofpoint says at least four hacking groups, some with ties to the Chinese government, are using a nearly identical exploit kit dubbed BlueMoon that chains two Chrome V8 vulnerabilities with a Windows kernel privilege-escalation flaw, delivered via phishing;…
Proofpoint identified a shared exploit kit, named BlueMoon, used by at least four hacking groups — described by Malwarebytes as espionage groups, some with ties to the Chinese government — targeting Chrome on Windows within days of one another. Attacks began with phishing emails leading to web pages that exploited two Chrome V8 vulnerabilities, followed by a Windows kernel privilege-escalation flaw used to escape browser protections and gain higher privileges, ultimately installing malware of the attacker's choice. A fully weaponized Chrome exploit chain has historically been a rare, high-value capability. According to Proofpoint, the Windows flaw affects Windows 10 (October 2018 Update and 2004), Windows Server 2019 and 2022, and the initial Windows 11 release; Ars Technica described the targets more generally as Windows 10, the initial Windows 11 release, and a later Windows version. The Chrome flaws were patched in Chrome Stable on September 3 and 8, 2026, and the Windows flaw was fixed in September's Patch Tuesday; all three vulnerabilities were actively exploited and added to CISA's KEV catalog. Note on timing: Ars Technica and Proofpoint state that all three vulnerabilities received patches within roughly 24 hours (of the exploitation activity), while Malwarebytes dates one of the Chrome patches to September 3, 2026. Proofpoint attributes the kit's rapid, widely shared deployment to the Chromium supply-chain patch gap — attackers weaponizing publicly visible upstream fixes — and to AI-assisted exploit development; Malwarebytes reports researchers found clues but no conclusive evidence that the kit was developed with AI assistance.
- Proofpoint named the shared kit BlueMoon; it chains two Chromium/Chrome V8 vulnerabilities with one Windows kernel privilege-escalation flaw.
- At least four hacking groups, some with ties to the Chinese government, used the same kit against Chrome on Windows within days of one another.
- Attacks began with phishing emails leading to web pages that exploited the Chrome flaws, followed by the Windows flaw to escape browser protections and gain higher privileges and install attacker-chosen malware.
- Windows flaw affects Windows 10 (October 2018 Update and 2004), Windows Server 2019 and 2022, and the initial Windows 11 release (per Proofpoint); Ars Technica described targets as Windows 10, initial Windows 11, and a later Windows…
- Chrome flaws were patched in Chrome Stable on September 3 and 8, 2026; the Windows flaw was fixed in September Patch Tuesday.
- All three exploited vulnerabilities were added to CISA's KEV catalog.
- Proofpoint links the rapid sharing of the kit to the Chromium supply-chain patch gap and AI-assisted exploit development; Malwarebytes says there are clues but no conclusive proof of AI assistance.
- A fully weaponized Chrome exploit chain has historically been a rare, high-value capability.
Coverage timelineoldest first · each row is one article
- · 6d ago4 groups caught using the same Chrome and Windows exploit kit
Ars Technica · Security· 85
Proofpoint says at least four groups, some China-linked, actively share the BlueMoon kit chaining two Chromium and one Windows kernel exploit.
- · 6d agoFour groups caught using the same Chrome and Windows exploit kit
Proofpoint Threat Insight· 80
Proofpoint reports at least four hacking groups, some China-linked, share the BlueMoon exploit kit chaining Chromium and Windows kernel vulnerabilities to install malware.
- · 6d agoBlueMoon exploit kit turns Chrome and Windows flaws into attacks
Malwarebytes Labs· 75
Proofpoint documents BlueMoon exploit kit used by four espionage groups to chain Chrome V8 and Windows flaws via phishing, all now in CISA's KEV.