Four hacking groups share BlueMoon exploit kit chaining Chrome and Windows bugs

Four hacking groups share BlueMoon exploit kit chaining Chrome and Windows bugs

Security firm Proofpoint said Wednesday that at least four hacking groups, some with ties to the Chinese government, are actively using a nearly identical exploit kit the firm has named BlueMoon. The kit targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows, letting the attackers who deploy it install malware of their choice.

BlueMoon chains three vulnerabilities together: two in Chromium and one in the Windows kernel. The kernel flaw affects Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities were patched in the 24 hours before Proofpoint's Wednesday report.

The pattern of use was unusual. Proofpoint said the attacks lacked the stealth found in many campaigns; hackers who find a new vulnerability more often exploit it sparingly, to keep it usable for longer. BlueMoon, by contrast, was developed and then deployed rapidly and shared across multiple threat actors within days, in a way that generated high detection signals instead of staying hidden.

Proofpoint offered two likely explanations for that speed. One is a patch gap in the Chromium supply chain: the span between when a fix becomes available from Chromium's own developers and when it actually reaches downstream browsers built on it, such as Chrome and Edge. The other is the growing use of AI, which the firm said can often spot vulnerabilities faster than discovery performed solely by humans. Proofpoint framed the pattern itself in stark terms, saying a fully weaponized Chrome exploit chain has historically been a high-value, rare capability, and that BlueMoon's rapid development and wide, fast sharing despite high detection signals may reflect a reduced cost and lower barrier to entry for this class of capability as AI agents increasingly enable threat actor exploit development. The firm added that the dynamic is particularly relevant for open source codebases such as Chromium, where upstream patches are publicly visible before downstream consumers apply them, giving attackers a window to reverse-engineer those patches and build working exploits ahead of the next stable release.

Proofpoint said the four groups targeted a wide range of organizations and companies, but the account available here breaks off just as it begins to list the groups and their specific targets. It likewise gives no CVE identifiers for the three chained vulnerabilities and does not say whether the four groups obtained BlueMoon independently or from a shared source.

Key facts

  • Proofpoint said Wednesday that at least four hacking groups, some with ties to the Chinese government, are using a nearly identical exploit kit the firm named BlueMoon.
  • BlueMoon chains three vulnerabilities, two in Chromium and one in the Windows kernel, letting attackers install malware of their choice; all three were patched in the 24 hours before Proofpoint's report.
  • The Windows kernel flaw affects Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.
  • The attacks lacked the stealth typical of most campaigns: BlueMoon was developed and then deployed rapidly and shared across multiple threat actors within days, generating high detection signals instead of staying hidden.
  • Proofpoint said the pattern may reflect a reduced cost and barrier to entry for this class of exploit as AI agents increasingly enable threat actor exploit development, alongside a patch gap in how Chromium's open source fixes reach downstream browsers.

Why it matters

A fully weaponized browser exploit chain has historically been, in Proofpoint's words, a high-value, rare capability. BlueMoon broke that pattern: it was built, deployed rapidly, and then shared across at least four separate hacking groups, some tied to the Chinese government, within days, generating high detection signals rather than staying hidden. Proofpoint frames this as a possible sign that AI is lowering the cost and skill needed to build this class of exploit, alongside a structural problem in how open source projects like Chromium get patched: fixes become visible to everyone, including attackers, before every downstream browser has actually applied them. Both point to the same shift: a capability that used to take one sophisticated group a long time to build, and to protect, may now be built once and used by several groups almost immediately.

Who it affects

Directly, anyone running the affected software before the patches landed: Chromium-based browsers such as Chrome and Edge, plus five specific Windows builds, Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. Proofpoint says the four groups using BlueMoon targeted a wide range of organizations and companies, though the account available here does not name those groups or list their specific targets. More broadly, it affects security teams responsible for patching Chromium-based browsers or the listed Windows versions, and it affects how the security industry talks about AI's role in offense, since Proofpoint names AI-assisted exploit development as a likely contributor rather than treating it as speculation alone.

How to use it

There is no product to buy here, only a patching deadline that has effectively already passed: Proofpoint says all three chained vulnerabilities were patched in the 24 hours before its Wednesday report. Anyone running Chrome, Edge or another Chromium-based browser, or any of the five listed Windows builds, should confirm those patches are installed rather than assume routine update cycles have already caught them, since a working exploit chain for the unpatched versions has already been shared among multiple threat actors.

How solid is it

The account rests entirely on Proofpoint's own research, presented through Ars Technica with a direct quotation from Proofpoint's findings. No individual researcher is named, only "researchers from security firm Proofpoint" collectively. Proofpoint is explicit that its two explanations for BlueMoon's speed, the Chromium patch gap and the growing use of AI, are hypotheses rather than confirmed causes: the account attributes both to "Proofpoint hypothesized" rather than stating them as settled fact. The story also does not name a specific AI tool, model or vendor behind either the attackers' or any defenders' use of AI.

Risks and caveats

The account available here cuts off just as it begins to list the four hacking groups and their targets, so their identities, sectors and countries are unknown from this material. Whether the four groups built BlueMoon independently or obtained it from a shared source or broker is not stated, only that it was shared across multiple threat actors. No CVE identifiers are given for the three chained vulnerabilities, and neither Google nor Microsoft, the vendors of the affected products, are quoted or described as responding. The claim that some of the four groups have ties to the Chinese government is Proofpoint's own attribution and is not independently corroborated here.

“BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development.”

— Proofpoint, on why BlueMoon spread so quickly across threat actors