Threat Intelligence

BlueMoon Exploit Kit Spreads Across Multiple State-Backed Spy Groups

The Hacker News · 10 Sept 2026
Key Takeaway Keep Chrome, other browsers, and Windows fully updated and train staff to spot phishing emails, since delayed patching creates a window attackers actively exploit.

Security researchers at Proofpoint have identified a previously unknown exploit kit named BlueMoon that combines vulnerabilities in Google Chrome and Microsoft Windows to compromise targeted systems. The kit was first observed being used by the China-aligned group APT31 in late August 2026, and within days several other espionage-focused groups, most with a suspected China connection, began using the same toolkit.

BlueMoon relies on phishing emails that lure victims into visiting a malicious website. Once there, two flaws in Chrome's V8 engine are exploited in sequence to run code and break out of the browser's security sandbox, followed by a Windows privilege escalation bug that allows attackers to inject further malicious code. Notably, the Chrome flaws were exploited as 'patch-gap' zero-days, meaning fixes existed in the public Chromium source code but had not yet reached released versions of Chrome, suggesting the attackers were closely monitoring upstream code changes.

Both affected vulnerabilities have since been patched, one by Google and the other by Microsoft in its September 2026 update. However, the fact that multiple unrelated espionage groups gained access to the same sophisticated exploit chain within a short window raises concerns about shared tooling or a common exploit broker among threat actors.

exploit kit Chrome vulnerability Windows vulnerability state-sponsored hacking phishing

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.