#APT31
📢 Des APT chinois exploitent une chaîne de zero-days Chrome/Windows pour déployer CLEANGULP

Rescana (rescana.com), publié le 23 septembre 2026. L'article est une alerte d'exploitation active basée sur des observations de terrain…

🟢 vérification factuelle haute
#APTChinois #CLEANGULP #Cyberveille
Des APT chinois exploitent une chaîne de zero-days Chrome/Windows pour déployer CLEANGULP
Rescana (rescana.com), publié le 23 septembre 2026. L'article est une alerte d'exploitation active basée sur des observations de terrain par des firmes de threat intelligence, dont Volexity. En septembre 2026, au moins deux groupes APT d'origine chinoise — UTA0560 et JungleBamboo (alias APT31, Violet Typhoon, TA412) — ont mené une campagne coordonnée d'espionnage cyber.
cyberveille.ch
September 28, 2026 at 9:00 PM
10/ "During [the current] period of close political rapprochement, attacks continued. Russian information security company Positive Technologies has linked APT31 to attacks on domestic IT contractors of government agencies in 2024–2025.
September 17, 2026 at 8:35 AM
A Chinese threat actor, UTA0560, exploited recent Chrome and Windows patches in a spear-phishing campaign targeting NGOs with a malicious JavaScript backdoor called GRIMWEDGE. #cybersecurity
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
thehackernews.com
September 17, 2026 at 3:32 AM
A spear-phishing link to a real .edu site used reflected XSS to bounce NGO staff into a three-bug Chrome and Windows zero-day chain ending in the GRIMWEDGE backdoor. No attachment, no macro, one click. #infosec #cybersecurity
China-Linked APT31 Exploits Chrome and Windows Zero-Day Chain to Deploy GRIMWEDGE
A spear-phishing link to a real .edu site used reflected XSS to bounce NGO staff into a three-bug Chrome and Windows zero-day chain ending in the GRIMWEDGE backdoor. No attachment, no macro, one click. #infosec #cybersecurity
captechgroup.com
September 15, 2026 at 12:44 PM
中国の攻撃者が、ChromeとWindowsのゼロデイ脆弱性を悪用し、GRIMWEDGEというバックドアをNGOに送り込んでいる。
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
thehackernews.com
September 15, 2026 at 11:37 AM
China-linked hackers used a Chrome-Windows zero-day chain and spear-phishing to hit NGOs, deploying the GRIMWEDGE backdoor. The same chain also spread SUPERSTOMP and the LONGTALE extension. #China #Chrome #Windows
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain To Deploy GRIMWEDGE
A Chinese threat actor tracked as UTA0560 used spear-phishing and a Chrome-Windows exploit chain to deliver the GRIMWEDGE JavaScript backdoor to NGOs. Around the same time, JungleBamboo (APT31) used the same chain to deploy SUPERSTOMP and the LONGTALE credential-stealing Chrome extension. #UTA0560 #GRIMWEDGE #JungleBamboo #APT31 #LONGTALE #SUPERSTOMP #Chrome #Windows #BlueMoon...
www.hendryadrian.com
September 15, 2026 at 9:30 AM
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

thehackernews.com/2026/09/chin...
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
thehackernews.com
September 15, 2026 at 5:51 AM
BlueMoon exploit kit is being rapidly reused by espionage groups to chain Chrome zero-days with a Windows privilege escalation flaw in opportunistic attacks across US, Vietnam, Indonesia, and Singapore. #BlueMoon #Vietnam #APT31
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
BlueMoon is a newly observed exploit kit that multiple espionage groups rapidly adopted to chain Chrome zero-days and a Windows privilege escalation flaw in rushed, opportunistic attacks. Proofpoint says it was first used by Violet Typhoon and then shared across other threat actors targeting organizations in the US, Vietnam, Indonesia, and...
www.hendryadrian.com
September 12, 2026 at 3:00 PM
BlueMoonエクスプロイトキット、ChromeとWindowsの最新ゼロデイを連鎖悪用

複数のサイバースパイグループが、BlueMoonと呼ばれる新種のエクスプロイトキットを使用していることが、サイバーセキュリティ企業Proofpointの報告で明らかになりました。展開の様子は場当たり的かつ急ごしらえに見えるということです。 中国と関係が深いAPTグループ「Violet Typhoon」(APT31、J
BlueMoonエクスプロイトキット、ChromeとWindowsの最新ゼロデイを連鎖悪用
複数のサイバースパイグループが、BlueMoonと呼ばれる新種のエクスプロイトキットを使用していることが、サイバーセキュリティ企業Proofpointの報告で明らかになりました。展開の様子は場当たり的かつ急ごしらえに見えるということです。 中国と関係が深いAPTグループ「Violet Typhoon」(APT31、J
blackhatnews.tokyo
September 12, 2026 at 11:23 AM
中国系ハッカー集団、ChromeとWindowsのゼロデイ脆弱性を連鎖利用しバックドア展開・認証情報窃取

Google Chromeおよびウィンドウズカーネルの新たに公表された脆弱性チェーンにより、標的を侵害し、スパイ活動用マルウェアを展開し、ブラウザの認証情報を盗み出すことが可能になっています。 Volexityによると、UTA0560とJungleBamboo(APT31、Violet Typhoon、TA412とし...
中国系ハッカー集団、ChromeとWindowsのゼロデイ脆弱性を連鎖利用しバックドア展開・認証情報窃取
Google Chromeおよびウィンドウズカーネルの新たに公表された脆弱性チェーンにより、標的を侵害し、スパイ活動用マルウェアを展開し、ブラウザの認証情報を盗み出すことが可能になっています。 Volexityによると、UTA0560とJungleBamboo(APT31、Violet Typhoon、TA412とし
blackhatnews.tokyo
September 12, 2026 at 7:58 AM
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft W…
#hackernews #microsoft #news
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
thehackernews.com
September 10, 2026 at 6:00 PM
BlueMoon exploit kits chained Windows and Chrome zero-days for RCE, sandbox escape, and privilege escalation in espionage campaigns targeting NGOs, defense firms, and Vietnamese manufacturers. #BlueMoon #Vietnam #Chrome
New 'BlueMoon' Kit Exploited Windows And Chrome Zero-day Flaws
Multiple cyber-espionage groups used the BlueMoon exploit kit to chain zero-day flaws in Microsoft Windows and Google Chrome for remote code execution, sandbox escape, and privilege escalation. Proofpoint and Volexity linked distinct BlueMoon campaigns to JungleBamboo, UTA0560, UNK_LateNight, and UNK_DoubleCheck, with targets including NGOs, U.S. aerospace and defense firms, and Vietnamese manufacturers. #BlueMoon #JungleBamboo #APT31 #VioletTyphoon #UTA0560 #UNK_LateNight #UNK_DoubleCheck #Chrome #MicrosoftWindows
www.hendryadrian.com
September 10, 2026 at 5:45 PM
🎶Blue Mooon🎵

it's been flying under the radar since 8/28, and finally the news is catching up. i should do something about that.

thehackernews.com/2026/09/four...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
thehackernews.com
September 10, 2026 at 4:14 PM
BlueMoon exploit kit chained Chrome and Windows flaws for espionage, enabling code execution, sandbox escape, and privilege escalation. First linked to APT31, then reused by other China-aligned clusters. #BlueMoon #APT31 #China
Four Spy Groups Used The Same Chrome And Windows Exploit Kit Within A Week
BlueMoon is a newly observed exploit kit used in espionage campaigns to chain Chrome and Windows vulnerabilities for code execution, sandbox escape, and privilege escalation. Proofpoint linked the first in-the-wild use to APT31 and said the kit quickly spread to other China-aligned clusters while leaving behind persistence mechanisms such as malicious...
www.hendryadrian.com
September 10, 2026 at 3:45 AM
🤖 New BlueMoon exploit kit chains Windows + Chrome flaws, used by four espionage groups within a week. First in-the-wild use attributed to China-aligned APT31.

https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
September 10, 2026 at 3:25 AM
Proofpoint says at least four China-aligned groups chained three zero-days in Chrome, Chromium browsers, and Windows to run espionage since late August, targeting NGOs, firms, and organizations across Asia and the U.S. #China #APT31 #ZeroDay
Chinese Espionage Groups Swarm To Exploit Triple-link Chain Of Zero-days
Proofpoint found at least four China-aligned threat groups chaining three zero-day flaws in Chrome, Chromium-based browsers, and Windows to carry out espionage since late August. The BlueMoon exploit chain has been used against NGOs, mining and commodity firms, U.S. aerospace companies, and organizations in Vietnam, Indonesia, and Singapore. #TA412 #VioletTyphoon #APT31 #BlueMoon #CVE-2026-85046 #CVE-2026-87491 #CVE-2026-85880 #UNK_LateNight #UNK_DoubleCheck #UNK_QuietRacket
www.hendryadrian.com
September 10, 2026 at 1:00 AM
中国系APT31が、ChromeとWindowsの脆弱性を悪用する「BlueMoon」キットを使用。エクスプロイトキットは4つのスパイグループが1週間以内に利用。
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
thehackernews.com
September 9, 2026 at 8:51 PM
Proofpoint found four state-aligned groups running the same exploit kit within a week, starting with APT31 on 28 August. BlueMoon chains a Chromium V8 zero-day with CVE-2026-85880, the Windows ALPC flaw Microsoft patched Tuesday. therecord.media/china-ha...
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
Proofpoint says four state-aligned clusters adopted the BlueMoon exploit chain within a week.
therecord.media
September 9, 2026 at 5:49 PM
Nieuwe exploitkit BlueMoon treft Amerikaanse organisaties, met vermoedelijke Chi

Sinds eind augustus 2026 is een nieuwe exploitkit genaamd BlueMoon actief, ingezet door minstens vier dreigingsgroepen die waarschijnlijk gelieerd zijn aan China. De eerste geregistreerde inzet vond plaats op 2...
Nieuwe exploitkit BlueMoon treft Amerikaanse organisaties, met vermoedelijke Chinese link
Sinds eind augustus 2026 is een nieuwe exploitkit genaamd BlueMoon actief, ingezet door minstens vier dreigingsgroepen die waarschijnlijk gelieerd zijn aan China. De eerste geregistreerde inzet vond plaats op 28 augustus 2026 door de groep TA412, ook bekend als Violet Typhoon of APT31. TA412 voerde spearphishing-aanvallen uit gericht op Amerikaanse non-profitorganisaties, mijnbouwbedrijven en grondstoffenhandelaren. Het doel was de installatie van een kwaadaardige browser-extensie genaamd GemStone. Deze extensie biedt backdoortoegang voor browserbewaking, inclusief keylogging, diefstal van cookies, het maken van screenshots en het onderscheppen van HTTP-verzoeken. BlueMoon maakt gebrui...
newsfacts.info
September 9, 2026 at 5:30 PM
BlueMoon was first used by TA412 (Violet Typhoon, APT31) on 28 August, with three more clusters following within days. We assess the majority to be 🇨🇳-aligned.
September 9, 2026 at 10:20 AM
Чешская контрразведка: атаки российских хакеров — «малоизощрённые» и «банальные». А вот взлом МИД Чехии китайской APT31 длился минимум два года. beebug.io/praga-nazval...
Контрразведка Чехии не впечатлилась российскими хакерами
В ежегодном отчёте атаки из Москвы называют «малоизощрёнными» и «банальными».
beebug.io
August 27, 2026 at 9:06 PM
💗エロゲ原画担当&サイン会のお知らせ💗
この度、アパタイトさんより
『口悪塩対応の汐谷さんは、なぜか俺をヌいてくれる』
の原画担当させて頂きました✨

そしてなんと、9月18日発売日に
初の【サイン会】も開催します❣

どうぞよろしくお願いします🌸
www.appetite-game.com/apt312/apt31...
July 31, 2026 at 1:37 PM