Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
-
Multiple espionage-motivated threat clusters have been observed deploying a previously undocumented exploit kit dubbed BlueMoon, which chains together several vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31, also known as Bronze Vinewood, Judgement Panda, and JungleBamboo.
Key points from the reporting:
- The campaign involved multiple espionage-motivated threat activity clusters rather than a single actor.
- BlueMoon is an exploit kit that chains multiple vulnerabilities together in Windows and Chrome.
- The kit was previously undocumented prior to this activity.
- The earliest observed in-the-wild deployment is linked to APT31, a China-aligned state-sponsored group with several tracked aliases.
No specific CVE identifiers or patch numbers were provided in the source material, so none are listed here. Organizations should monitor vendor advisories for Chrome and Windows updates and prioritize timely patching of both browsers and endpoints, given the exploit kit's reliance on chaining multiple flaws across both platforms.
Source: The Hacker News
Has anyone seen related telemetry or additional details on the BlueMoon exploit chain in their environment?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login