4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.
A single exploit kit, dubbed BlueMoon, is currently being utilized by four distinct hacking groups, some of which are believed to be affiliated with the Chinese government. Proofpoint, a security firm, identified the kit and described its multi-stage attack methodology. The BlueMoon exploit kit capitalizes on three vulnerabilities - two in the Chromium-based browsers and one in the Windows kernel.
These vulnerabilities are all patched within a 24-hour window, yet the attackers have managed to deploy the kit rapidly and widely. The campaign appears to lack the stealth typically associated with such exploits, suggesting a deliberate strategy rather than an opportunistic attack. Proofpoint posits that this could be an attempt to exploit what they term a "patch gap" in the Chromium supply chain.
This term refers to the time lag between when a security patch becomes available and when it is integrated into popular browsers like Chrome and Edge. Another possible factor contributing to the BlueMoon kit's widespread usage is the application of artificial intelligence. AI can often identify software vulnerabilities before they are officially disclosed, allowing cybercriminals to exploit these weaknesses ahead of their official discovery.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.