Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The BlueMoon Exploit Kit: A Threat to Global Cybersecurity


Four groups caught using the same Chrome and Windows exploit kit, highlighting the growing threat of nation-state-sponsored hacking and the need for continued vigilance and cooperation in cybersecurity. The BlueMoon exploit kit is a fully weaponized Chrome exploit chain that targets critical vulnerabilities in Chromium-based browsers and older versions of Windows, chaining three vulnerabilities together to install malware of their choice.

  • The BlueMoon exploit kit is a highly sophisticated attack tool that targets critical vulnerabilities in Chromium-based browsers and older versions of Windows.
  • The kit exploits a "patch-gap" in Windows 10 and other operating systems, allowing attackers to install malware before patches are available.
  • The attack was carried out by at least four groups, including state-sponsored threat actors, who targeted a wide range of organizations and companies.
  • The use of AI in exploit kit development has made this capability more accessible and affordable.
  • The kit is likely to continue being used despite patches being rolled out, due to its ease of adoption and the involvement of financially motivated threat actors.



  • The world of cybersecurity has been dealt a significant blow with the discovery of the BlueMoon exploit kit, a nearly identical exploit kit being actively used by at least four hacking groups, some of which have ties to the Chinese government. According to researchers from security firm Proofpoint, the BlueMoon exploit kit targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows, chaining three vulnerabilities together to install malware of their choice.

    The BlueMoon exploit kit exploits two Chromium vulnerabilities and one in the kernel of Windows 10, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours, but the attackers used this "patch-gap" to their advantage, exploiting the vulnerabilities before they were fixed. The use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans, is also believed to have played a role in the rapid deployment and sharing of the exploit kit.

    The attackers, which include four groups, targeted a wide range of organizations and companies, including TA412, a China-aligned state-sponsored threat actor indicted by the US government in 2024, UNK_LateNight, a China-aligned espionage group, UNK_DoubleCheck, and UNK_QuietRacket activity. The attacks lacked the stealth found in many campaigns, and the attackers wanted to exploit newly discovered vulnerabilities sparingly to lengthen their longevity.

    The BlueMoon exploit kit is a fully weaponized Chrome exploit chain, which has historically been a high-value, rare capability. However, with the use of AI agents increasingly enabling threat actor exploit development, this capability has become more accessible and affordable. The BlueMoon exploit kit was developed, deployed rapidly, and shared across multiple threat actors within days, which had high detection signals.

    The researchers believe that the BlueMoon exploit kit may continue to be used despite the patches being rolled out across all Chromium-based browsers. The ease of adoption, combined with the fact that the kit is being used by espionage-motivated and financially motivated threat actors, makes it likely to proliferate further.

    The discovery of the BlueMoon exploit kit highlights the need for continued vigilance and cooperation among cybersecurity professionals and governments to combat the growing threat of nation-state-sponsored hacking. As the threat landscape continues to evolve, it is essential to stay ahead of the curve and develop effective strategies to mitigate these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-BlueMoon-Exploit-Kit-A-Threat-to-Global-Cybersecurity-ehn.shtml

  • https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/

  • https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html

  • https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-days.html


  • Published: Thu Sep 10 09:35:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us