#chromeZeroDay
Several Chinese Hacking Groups Observed Using Identical Chrome Zero-Day Exploit #BlueMoonExploitKit #ChromeZeroDay #ChromiumVulnerability
Several Chinese Hacking Groups Observed Using Identical Chrome Zero-Day Exploit
Based on cybersecurity firm Proofpoint, four cyber-espionage groups, most of which are linked to Chinese state intelligence, have been exploiting the same previously unknown Chrome vulnerability since late August, according to the firm. The activity involved an exploit kit, referred to as BlueMoon, that was used on U.S. defense contractors, non-profit organizations, and government agencies throughout Southeast Asia.  There were separate campaigns operated by each group that targeted different targets, deployed different malware and utilized different command-and-control infrastructure, but utilized the same exploit kit for the compromise of Chrome browsers. According to Proofpoint, two additional groups may have utilized BlueMoon, suggesting that its reach may extend far beyond activities identified so far.  The use of the kit has raised questions regarding how different threat groups were able to achieve the same capability so quickly. A number of possibilities have been explored by researchers, including Chinese government sources, shared contractors, and commercial providers providing offensive tools to multiple actors.  Proofpoint has not yet identified a definitive source for the exploit kit BlueMoon exploited a vulnerability in Chromium, the open-source project that runs Chrome, to exploit this vulnerability. The corresponding changes to Chrome released a few weeks later, even though a vulnerability had been fixed in Chromium in early August. As a result of access to public code changes during that period, attackers were able to assess the fix and develop an exploit to discover the underlying weakness.  Until an upstream fix was released to Chrome users, there was a narrow window for exploitation. According to Proofpoint researchers, reverse engineering and weaponizing patches within such a short period of time was not uncommon before, but the BlueMoon activity indicates that attackers are developing more rapid exploits from publicly available fixes. By combining multiple browser vulnerabilities with a Windows vulnerability, BlueMoon is able to gain control of a targeted system.  Once the browser compromise has been completed, it is handed over to malware selected by the threat group that is employing it. APT31, also known as TA412, is the first confirmed user of BlueMoon. The group used it to attack U.S. non-governmental organizations, mining companies, and commodity traders via phishing messages.  The exploit chain for BlueMoon was based upon two vulnerabilities in Chrome's V8 JavaScript and WebAssembly engines, followed by a privilege-escalation flaw in Windows. The attackers were able to break out of Chrome's security sandbox using the browser vulnerabilities, and then used the Windows vulnerabilities to gain higher privileges on affected systems by exploiting the Windows flaw.  By injecting code into the Chrome broker process after the chain had completed, BlueMoon could retrieve executables and execute them from the temporary directory of the system using the built-in curl utility. Proofpoint identified several packaging variants of the kit, but the key exploitation sequence and loading process remained largely unchanged. Additionally, evidence has been found to indicate artificial intelligence may have played a role in the rapid development of BlueMoon.  During the development process, researchers found detailed debugging comments, diagnostic information, and a Markdown handover document. Several of the references to Google V8 challenges were not sufficient to establish whether or not artificial intelligence was responsible for developing the exploit.  According to Proofpoint, however, the evidence was insufficient to establish how artificial intelligence was used. Especially significant is the timing of the activity because it appears that the attackers used publicly available Chromium fixes before those fixes were released in stable browser versions. While many systems were still vulnerable to attacks, exploit developers had the opportunity to examine the patches, identify the underlying weaknesses, and prepare attacking code to exploit these vulnerabilities.  A fix has been provided for all three vulnerabilities used by BlueMoon, including the privilege-escalation flaw in Microsoft's September 2026 security updates for Windows. Despite the fact that security updates are still being distributed across Chromium-based browsers during this period, the exploit kit may continue to pose a threat during this time.  The rapid movement of BlueMoon between multiple espionage campaigns could indicate that the costs of developing advanced browser exploits are declining, according to Proofpoint. Furthermore, the researchers noted that the kit is not limited to Chinese activities, since it is relatively straightforward to deploy. This makes it useful to other espionage and financially motivated threat actors as well.
dlvr.it
September 13, 2026 at 5:00 PM
📢 BlueMoon : quatre acteurs étatiques exploitent le même kit Chrome zero-day en 12 jours

Cet article relaie une analyse détaillée de Proofpoint, avec contributions de Google Threat Intelligence Group, Microsoft MSTIC et…

🟢 vérification factuelle haute
#BlueMoon #ChromeZeroDay #Cyberveille
BlueMoon : quatre acteurs étatiques exploitent le même kit Chrome zero-day en 12 jours
Cet article relaie une analyse détaillée de Proofpoint, avec contributions de Google Threat Intelligence Group, Microsoft MSTIC et Volexity, portant sur un kit d'exploitation baptisé BlueMoon utilisé par quatre acteurs étatiques distincts en moins de deux semaines.
cyberveille.ch
September 11, 2026 at 10:00 PM
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps.

#ChromeZeroDay #JungleBamboo #UTA0560 #CyberEspionage #InfoSec #Malware
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
At a glance
securityonline.info
September 10, 2026 at 1:13 PM
Google rolled out another emergency Chrome patch for an actively exploited V8 engine flaw. Just another Tuesday interrupting our cold tea.

#ChromeZeroDay #PatchTuesday
September 5, 2026 at 11:17 AM
PayPal breach, Chrome 0-Day, BeyondTrust exploit: major cybersecurity incidents this week. #CyberSecurity #DataBreach #ChromeZeroDay #BeyondTrust #PayPal #Cloudflare thedailytechfeed.com/major-cybers...
July 5, 2026 at 2:28 PM
📰 Google Rilis Patch Darurat untuk Celah Keamanan Zero-Day Kelima Chrome di Tahun Ini

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/09/google-tambal-celah-zero-day-kelima-chrome-cve-2026-11645/

#asl
rB#aslrBypassm#chromeZeroDay2#cve11645 #googl#googleChromel#googleTagC#heapCorruptio
June 9, 2026 at 8:16 AM
March 13, 2026 at 5:01 PM
🚨 URGENT: Google Chrome zero-day (CVE-2025-5419) with 8.8 severity score is being actively exploited - update to version 137.0.7151.68+ NOW to prevent system compromise and data theft! 🔒
https://biggo.com/news/202506041652_Chrome_Zero_Day_Vulnerability_Patch

#GoogleChrome #ChromeZeroDay
June 4, 2025 at 5:16 PM
March 18, 2026 at 8:07 PM
🌋 $55k for a V8 type confusion vuln proves Google's still building Chrome on C++'s memory corruption roulette. Your banking sessions are one pointer error away from North Korean crypto heists. But hey, performance! #infosec #ChromeZeroDay
December 12, 2024 at 7:05 PM
Operation ForumTrol targets Russian scholars with a new phishing campaign, exploiting Chrome zero-day vulnerabilities. Stay vigilant and update your systems. #CyberSecurity #Phishing #APT #ChromeZeroDay Link: thedailytechfeed.com/forumtrol-ap...
December 18, 2025 at 4:48 PM
March 18, 2026 at 8:07 PM
Google patches Chrome zero-day CVE-2025-10585—an active V8 engine exploit. Type confusion flaw allows silent code execution. Update now. 🛠️🌐 #ChromeZeroDay #ExploitAlert
Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
Google releases critical Chrome update patching zero-day CVE-2025-10585, discovered Sept 16, to block active V8 JavaScript engine exploits worldwide.
buff.ly
September 18, 2025 at 3:06 PM