BlueMoon is a newly observed exploit kit used in espionage campaigns to chain Chrome and Windows vulnerabilities for code execution, sandbox escape, and privilege escalation. Proofpoint linked the first in-the-wild use to APT31 and said the kit quickly spread to other China-aligned clusters while leaving behind persistence mechanisms such as malicious extensions and scheduled tasks. #BlueMoon #APT31 #GemStone #GhostChromeX #ShadowPad
Keypoints
- BlueMoon chains Chrome and Windows vulnerabilities to deliver multi-stage attacks.
- APT31 was the first known group to use BlueMoon in the wild.
- Several other China-aligned espionage clusters adopted the exploit kit within days.
- The attacks used phishing, malicious links, DLL sideloading, and payload downloaders.
- Targeted systems may remain compromised even after browser patching due to persistence artifacts.
Read More: https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html