AI News Feed
Market watch
Cybersecurity

Proofpoint Ties Four Hacking Groups to Shared BlueMoon Exploit Kit

Proofpoint says four hacking groups, some tied to China, used the same BlueMoon kit to exploit Chrome and Windows flaws patched in 24 hours.

BlueMoon exploits two Chromium vulnerabilities and one vulnerability in the kernel of several Windows versions, Proofpoint said. The affected Windows releases include Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours, Ars Technica reported.

The attacks lacked the stealth found in many campaigns. Hackers more often want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a "patch gap" in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans, the researchers said.

The article described the kit as rapidly deployed and widely shared. It said at least four hacking groups used it, and that some of those groups have ties to the Chinese government. Proofpoint's researchers said the chain could install malware of the attackers' choice. The three flaws covered two Chromium vulnerabilities and one Windows kernel vulnerability, and patches for all three arrived within the past 24 hours.