Skip to content
Auto-CTI
Back to today
NEW APT31 CRITICAL C3

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

C The Hacker News ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Multiple state-sponsored APT groups, including China-aligned APT31, are deploying a newly discovered exploit kit (BlueMoon) that chains multiple Windows and Chrome vulnerabilities to compromise targets in Western countries.

Description

BlueMoon is a previously undocumented exploit kit that chains vulnerabilities in Microsoft Windows and Google Chrome. The kit is deployed by at least four distinct espionage-motivated APT groups, including the China-aligned APT31. Its first wild use demonstrates coordinated efforts among multiple state-sponsored actors to exploit shared vulnerabilities within a short timeframe (one week). This indicates active, ongoing campaigns against Western infrastructure and confirms that exploit kits are shared across national boundaries within the APT community.

Risk score

85
strategic relevance
0.85

Path: strategic

ESC