Sep 10, 2026
ManyPress

Advertisement

Technology

Security researchers have identified a new exploit kit named BlueMoon that targets vulnerabilities in Chromium browsers and Windows, used by at least four different hacking groups.

ManyPress

ManyPress

ManyPress Editorial

2 min readSource:Ars Technica
Four Hacking Groups Using Same Chrome and Windows Exploit Kit

Key facts

  • The BlueMoon exploit kit chains three vulnerabilities to facilitate malware installation.
  • Affected Windows versions include Windows 10, Windows 11, and several Server editions.
  • Proofpoint researchers observed that the exploit kit was deployed and shared among four groups within days.
  • The use of AI may be accelerating the discovery and development of these exploit chains.
  • Patches for the identified vulnerabilities were made available within the 24 hours prior to the announcement.

Security firm Proofpoint reported on Wednesday that four distinct hacking groups are using a shared exploit kit, dubbed BlueMoon, to target vulnerabilities in Chromium-based browsers and Windows. The kit chains three separate vulnerabilities together to allow attackers to install custom malware on targeted systems. Some of the groups involved in these campaigns have suspected ties to the Chinese government.

Technical Scope and Vulnerabilities

The BlueMoon kit exploits two vulnerabilities within Chromium and one in the Windows kernel. Affected systems include Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. Patches for all three vulnerabilities were released within the 24 hours preceding the report.

Exploitation Trends and AI Usage

Researchers noted that the attacks were unusually visible, lacking the stealth typically associated with high-value exploit campaigns. Proofpoint suggests the attackers aimed to capitalize on the 'patch gap' between when a fix is developed for Chromium and when it is integrated into browsers like Chrome and Edge. The rapid development and sharing of the kit among multiple actors may indicate that AI tools are lowering the barrier to entry for creating such exploits, particularly by helping attackers reverse-engineer publicly available patches.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Ars Technica.

Technology