Exploit Kit Bluemoon: Chinese Hackers Attack Windows Users
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The Bluemoon exploit kit is actively used by Chinese hackers against Windows users and poses an immediate threat to manufacturing environments.
Description
The Chinese exploit kit Bluemoon is being used in active attack operations against Windows users. The kit targets vulnerabilities in Windows systems and is used as a vector for initial access into networks. The campaign exhibits attributes consistent with state-supported Chinese threat actors. Windows Server 2022, 2019, and standard Windows installations are primary attack targets. The threat is not geographically limited and targets critical infrastructure and industrial facilities.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 15.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational