Skip to content
Auto-CTI
Back to all deep dives
MALWAREBYTES

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

HIGH Four unnamed espionage groups (nation-state or state-sponsored) BlueMoon exploit-kit Chrome Windows

Strategic summary

The BlueMoon exploit kit combines two Chrome V8 JavaScript engine vulnerabilities and a Windows vulnerability to execute code with elevated privileges after phishing clicks. Proofpoint observed four espionage groups using the same exploit chain within days of each other after upstream fixes became publicly visible. All three vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog. The report shows attackers analyze patches and move faster than many users expect, so actively exploited vulnerabilities should be prioritized.

Key findings

  • BlueMoon uses two Chrome V8 vulnerabilities and one Windows vulnerability to bypass browser protections and gain higher privileges after a phishing click.
  • Four espionage groups used the same exploit chain within days, indicating rapid dissemination after publicly visible upstream fixes.
  • All three vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
  • Researchers found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance.
  • The gap between upstream fix and widespread protection is increasingly valuable to attackers, so prompt updates and prioritization based on the KEV list are critical.

Relevance for you

Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.

Risk score

17
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC