Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Four Groups of Hackers Caught Using the Same Exploit Kit Targeting Chrome and Windows


Four groups of hackers have been caught using the same exploit kit, dubbed "BlueMoon," which targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows. The kit has been found to be widely used and visible, lacking the stealth typically associated with hacking campaigns. The use of AI and the "patch gap" in the Chromium supply chain have contributed to the rapid development and sharing of the kit, making it a high-value, rare capability that is now more accessible to threat actors.

  • Four groups of hackers have been caught using the BlueMoon exploit kit, which targets critical vulnerabilities in Chromium-based browsers and older versions of Windows.
  • The exploit kit allows attackers to install malware of their choice by chaining three vulnerabilities together.
  • The vulnerabilities exploited in the kit are two Chromium vulnerabilities and one in the kernel of Windows 10, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.
  • The attacks lacked stealth, with hackers opting to exploit newly discovered vulnerabilities to lengthen their longevity.
  • The widespread use of the BlueMoon exploit kit may continue due to its ease of adoption and widespread sharing.
  • The kit's widespread use highlights the importance of patching and the need for threat actors to adapt to changing environments.



  • Four groups of hackers have been caught using the same exploit kit, dubbed "BlueMoon," which targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows. The exploit kit, which was developed, deployed rapidly, and shared across multiple threat actors within days, has been found to be widely used and visible, lacking the stealth typically associated with hacking campaigns.

    According to researchers from security firm Proofpoint, the BlueMoon exploit kit chains three vulnerabilities together, allowing attackers to install malware of their choice. The vulnerabilities exploited in the kit are two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

    The attacks lacked the stealth typically found in many campaigns, with hackers instead opting to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Researchers believe that a "patch gap" in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge, may be a contributing factor to the widespread use of the exploit kit.

    Furthermore, the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans, is also likely to have played a role in the rapid development and sharing of the exploit kit. Proofpoint noted that a fully weaponized Chrome exploit chain has historically been a high-value, rare capability, but that the BlueMoon kit has reduced the cost and barrier to entry for this class of capability, making it more accessible to threat actors.

    The four groups targeted a wide range of organizations and companies, including TA412, a China-aligned state-sponsored threat actor indicted by the US government in 2024 on behalf of China's civilian foreign intelligence agency, UNK_LateNight, a second China-aligned espionage group, UNK_DoubleCheck, a third group that targeted a Vietnamese manufacturing entity, and UNK_QuietRacket, an activity targeted Singapore and Indonesia.

    Both vulnerabilities targeting Chrome resided in V8, Google's open source JavaScript engine, with the attackers exploiting a V8 type confusion bug and a separate sandbox escape to execute remote code. They then used a local privilege escalation in older versions of Windows to allow the malicious code to run with system rights.

    The first V8 vulnerability is tracked as CVE-2026-85046, and the Windows bug is tracked as CVE-2026-85880. Google does not assign CVE designations for V8 sandbox escapes. Researchers from Proofpoint noted that both vulnerabilities were "patch-gap" zero-days at the time of the observed activity, meaning they were known vulnerabilities that had not yet been patched in the latest stable releases of Chrome and Chromium-based browsers available to the public.

    The BlueMoon exploit kit may continue to be used despite the patches, as it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers. The ease of adoption and widespread sharing of the kit have made it a high-value, rare capability, but one that is now more accessible to threat actors.

    In conclusion, the widespread use of the BlueMoon exploit kit highlights the importance of patching and the need for threat actors to adapt to changing environments. The use of AI and the "patch gap" in the Chromium supply chain have contributed to the rapid development and sharing of the kit, making it a high-value, rare capability that is now more accessible to threat actors.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Four-Groups-of-Hackers-Caught-Using-the-Same-Exploit-Kit-Targeting-Chrome-and-Windows-ehn.shtml

  • https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/


  • Published: Wed Sep 9 18:12:04 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us