Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Mind the patch gap, please and thank you
At least four espionage groups, many with suspected ties to China, are employing a new exploit kit that exploits two Chromium-based browser flaws and a Windows vulnerability to infiltrate organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at Proofpoint, stated that the researchers are uncertain about the exact targets and method of access, with fewer than 20 organizations globally targeted so far, though the actual number is likely higher.
Proofpoint's threat hunters discovered the kit, named BlueMoon, which was first observed on August 28. TA412, a Beijing-backed cyberespionage group linked to China's Ministry of State Security, used BlueMoon to repeatedly target NGOs, mining companies, and commodity trading firms in the US. TA412, previously charged by US prosecutors for breaking into various critical infrastructure networks, email accounts, and cloud storage, is not the only group using BlueMoon, as several other China-nexus attackers have adopted the exploit kit within days.
BlueMoon's attack chain involves a phishing email that tricks victims into clicking a malicious link, triggering the V8 type confusion and sandbox escape vulnerabilities, and then downloading multiple payloads, including browser surveillance malware and credential-stealing backdoors.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.