A nearly identical exploit kit, dubbed BlueMoon by security researchers, is currently being leveraged by at least four distinct hacking groups—including some linked to the Chinese government—to target critical vulnerabilities in Chromium-based browsers and older versions of Microsoft Windows.
In a report released Wednesday, cybersecurity firm Proofpoint detailed how BlueMoon chains together three separate vulnerabilities, allowing attackers to deploy custom malware payloads. The toolkit exploits two zero-day flaws in Chromium and one in the Windows kernel affecting systems running Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and early versions of Windows 11. Notably, all three vulnerabilities have since received patches within the past 24 hours.
Widespread Use Despite High Risk
Despite its effectiveness, the campaign lacks the stealth typically employed in sophisticated cyberattacks. Instead of conserving these vulnerabilities for long-term use, the attackers deployed them broadly and quickly. Researchers suspect this approach stems from exploiting what they refer to as a “patch gap” within the Chromium ecosystem—the interval between when developers release a patch and when it is fully implemented across browsers like Chrome and Edge.
Additionally, Proofpoint suggests that recent advances in artificial intelligence may be enabling threat actors to identify and weaponize vulnerabilities at an accelerated pace, outpacing traditional human-driven discovery methods.
This combination of factors likely drove the rapid deployment of BlueMoon across multiple actor groups. As Proofpoint explained:
A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.
The affected groups targeted a diverse array of organizations spanning various sectors. While the specific list of targeted entities remains incomplete, the breadth of victims underscores the scale and urgency of the threat posed by BlueMoon.
Also Read
- NASA Selects Relativity Space For Terran R Launch Service Under New NLS II Agreement
- Massachusetts hits data centers with new clean power rules
- Lasker Awards Honor Breakthroughs in Sleep Biology, Hemophilia Therapy, and Parkinson’s Advocacy
- Six Chinese AI Firms Face US Allegations of Closely Copying Frontier Models


