Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
C The Hacker News ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Multiple state-sponsored APT groups, including China-aligned APT31, are deploying a newly discovered exploit kit (BlueMoon) that chains multiple Windows and Chrome vulnerabilities to compromise targets in Western countries.
Description
BlueMoon is a previously undocumented exploit kit that chains vulnerabilities in Microsoft Windows and Google Chrome. The kit is deployed by at least four distinct espionage-motivated APT groups, including the China-aligned APT31. Its first wild use demonstrates coordinated efforts among multiple state-sponsored actors to exploit shared vulnerabilities within a short timeframe (one week). This indicates active, ongoing campaigns against Western infrastructure and confirms that exploit kits are shared across national boundaries within the APT community.
Risk score
- strategic relevance
- 0.85
Path: strategic