Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Mind the patch gap, please and thank you
The BlueMoon exploit kit, targeting Chrome and Windows, is linked to at least four espionage groups, most with suspected ties to China. The kit exploits a combination of Chromium-based browser flaws and a Windows bug to infiltrate organizations in the US and Southeast Asia, with fewer than 20 organizations globally impacted. The first observed use of BlueMoon occurred on August 28, when a Beijing-backed group known as TA412 targeted NGOs, mining companies, and commodity trading firms.
BlueMoon was developed and deployed rapidly, reflecting the reduced cost and barrier to entry for exploit capabilities enabled by AI agents. A Google spokesperson declined to comment, while Microsoft patched the Windows bug on Tuesday.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.