Multiple cyber-espionage groups used the BlueMoon exploit kit to chain zero-day flaws in Microsoft Windows and Google Chrome for remote code execution, sandbox escape, and privilege escalation. Proofpoint and Volexity linked distinct BlueMoon campaigns to JungleBamboo, UTA0560, UNK_LateNight, and UNK_DoubleCheck, with targets including NGOs, U.S. aerospace and defense firms, and Vietnamese manufacturers. #BlueMoon #JungleBamboo #APT31 #VioletTyphoon #UTA0560 #UNK_LateNight #UNK_DoubleCheck #Chrome #MicrosoftWindows
Keypoints
- BlueMoon is a modular exploit kit used in multiple cyber-espionage operations.
- It chains Chrome and Windows zero-days for code execution and privilege escalation.
- Proofpoint linked BlueMoon use to JungleBamboo in spearphishing attacks starting August 28.
- Volexity observed similar activity from UTA0560 targeting NGO customers on September 1.
- Other BlueMoon clusters targeted U.S. aerospace and defense firms and Vietnamese manufacturers.