VYPR
researchPublished Sep 9, 2026· 1 source

Multiple Chinese Hacking Groups Co-opt Identical Chrome Zero-Day Exploit

At least four Chinese state-aligned cyber-espionage groups are leveraging the same novel exploit kit, 'BlueMoon,' to target organizations with a zero-day vulnerability in Google Chrome.

Multiple Chinese state-linked cyber-espionage groups have been observed exploiting a previously unknown zero-day vulnerability in Google Chrome, according to a report by cybersecurity firm Proofpoint. At least four distinct groups, and potentially two more, have been identified using the same exploit kit, codenamed 'BlueMoon,' to compromise Chrome browsers and deploy malware against a range of targets. These targets include U.S. defense contractors, non-governmental organizations, and government agencies in Southeast Asia, indicating a broad espionage campaign.

The coordinated use of the identical exploit kit by separate groups raises significant questions about its origin. Researchers at Proofpoint noted that the code within the BlueMoon kit is practically identical, down to variable naming and comments, strongly suggesting it was not developed in parallel by each group. This pattern aligns with previous observations where different Chinese-linked hacking operations gain access to the same offensive tooling around the same time, pointing towards a shared supplier, government provision, or a commercial market selling the exploit.

The BlueMoon exploit kit capitalizes on a vulnerability that had been fixed in Chromium, the open-source project underlying Chrome, in early August. However, the fix took approximately four weeks to propagate to the stable version of the Chrome browser. This 'patch gap' provided a critical window for attackers to analyze the public code changes, identify the vulnerability, and weaponize an exploit before most users were protected.

"Historically, that four-week gap has been pretty reasonable," said Mark Kelly, a threat researcher at Proofpoint. "That seems to no longer be the case." He added that the rapid weaponization of the patch, within this timeframe, is a concerning development. Google's recent shift to a two-week release cycle for Chrome aims to mitigate such exploitation windows by delivering security fixes more rapidly.

The BlueMoon exploit kit is a multi-stage attack, combining two browser flaws with a Windows vulnerability to achieve initial system compromise. Once a victim's machine is compromised, the kit facilitates the deployment of custom malware chosen by the specific hacking group. Proofpoint observed that the final stage of the attack, which involves downloading malicious files using the common 'curl' command-line tool, is surprisingly crude and offers multiple opportunities for security software detection. This apparent haste is attributed to the race against the incoming Chrome patch.

Among the identified groups using BlueMoon is TA412, also known as APT31, Violet Typhoon, and RedBravo. This group, previously targeted by U.S. indictments and sanctions, deployed the exploit against U.S. NGOs and commodity traders, using lures such as fake internship inquiries. They installed a malicious browser extension disguised as Google's Gemini AI assistant, which functioned as a surveillance and credential-theft backdoor.

Other groups, tracked as UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, also utilized the BlueMoon kit for their respective operations. UNK_LateNight targeted U.S. aerospace and defense companies, while UNK_DoubleCheck focused on a Vietnamese manufacturer. UNK_QuietRacket targeted organizations in Indonesia and Singapore. While some groups are suspected China-aligned, Proofpoint has not definitively attributed all of them, noting that further investigation is ongoing.

Proofpoint also noted potential AI involvement in the development of the BlueMoon exploit kit, citing debugging comments that resemble AI interactions and references to documents used for maintaining AI context. The firm suggests that AI may be accelerating the process of turning public software fixes into functional exploits, a trend that could lower the barrier to entry for sophisticated cyberattacks.

Synthesized by Vypr AI