Skip to content
Auto-CTI
Back to today
NEW Four unnamed espionage groups (nation-state or state-sponsored) HIGH C3

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

C Malwarebytes ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.

Description

The BlueMoon exploit kit chains together Chrome and Windows vulnerabilities that were deployed by at least four espionage groups within days of each other following disclosure. Proofpoint researchers documented the coordinated use of this exploit chain, indicating rapid adoption of newly disclosed vulnerabilities by state-sponsored actors. All three affected vulnerabilities were added by CISA to its KEV (Known Exploited Vulnerabilities) catalog, confirming they are being actively exploited in real-world attacks. The campaign underscores the risk of delayed patching, as threat actors often weaponize security updates and their fixes faster than organizations can deploy them.

Risk score

17
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC