4 groups caught using the same Chrome and Windows exploit kit



A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint said:

A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.

The four groups targeted a wide range of organizations and companies. The groups and targets included:



Source link

  • Related Posts

    Automattic’s board forces CEO Matt Mullenweg into leave of absence

    Matt Mullenweg, the founder and CEO of Automattic, best known as the parent company of WordPress.com, has been put on a leave of absence by his board against his will,…

    Continue reading
    Muse, The Band, Lost Its Social Media Handles To Muse, Meta’s New AI Agent

    Muse, Meta’s newly-released AI agent, is now using social media handles once controlled by Muse, the English rock band. The exact circumstances surrounding how the accounts changed hands are unclear,…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Automattic’s board forces CEO Matt Mullenweg into leave of absence

    Automattic’s board forces CEO Matt Mullenweg into leave of absence

    Sam Darnold exits Seahawks-Patriots season opener with hip injury, ruled out

    Sam Darnold exits Seahawks-Patriots season opener with hip injury, ruled out

    Valheim 1.0’s Steam player count soars to a huge 5-year high, but it’s not enough to beat the viral survival game’s early access peak

    Valheim 1.0’s Steam player count soars to a huge 5-year high, but it’s not enough to beat the viral survival game’s early access peak

    Andrew Garfield Answers Your Questions About His Long Hair

    Andrew Garfield Answers Your Questions About His Long Hair

    Tate brothers to stay jailed on rape and sex-trafficking charges, judge rules

    Tate brothers to stay jailed on rape and sex-trafficking charges, judge rules

    Ken Sim’s former party mates officially in race to beat him

    Ken Sim’s former party mates officially in race to beat him