Skip to content
Auto-CTI
Back to today
NEW Chinese State-Sponsored APT (unattributed) HIGH C3

Exploit Kit Bluemoon: Chinese Hackers Attack Windows Users

C Golem.de - Security ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The Bluemoon exploit kit is actively used by Chinese hackers against Windows users and poses an immediate threat to manufacturing environments.

Description

The Chinese exploit kit Bluemoon is being used in active attack operations against Windows users. The kit targets vulnerabilities in Windows systems and is used as a vector for initial access into networks. The campaign exhibits attributes consistent with state-supported Chinese threat actors. Windows Server 2022, 2019, and standard Windows installations are primary attack targets. The threat is not geographically limited and targets critical infrastructure and industrial facilities.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC