4 groups caught using the same Chrome and Windows exploit kit



A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint said:

A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.

The four groups targeted a wide range of organizations and companies. The groups and targets included:



Source link

  • Related Posts

    ‘The Shards’ Finale Explained: Who Is the Trawler?

    The first season of Ryan Murphy‘s soapy, stylish and campy adaptation of Bret Easton Ellis’s novel The Shards has come to an end. If he gets his way, there will…

    Continue reading
    The incomplete history of Duo devices

    Apple announced the company’s first device with a folding screen today, the iPhone Duo, but that’s where the firsts end. The Duo is not only far from the first foldable…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    ‘The Shards’ Finale Explained: Who Is the Trawler?

    ‘The Shards’ Finale Explained: Who Is the Trawler?

    Pile cards on top of each other and watch the magic happen in the textured and chunky roguelike deckbuilder Stack Order

    Pile cards on top of each other and watch the magic happen in the textured and chunky roguelike deckbuilder Stack Order

    Global temperatures hit record highs as El Niño strengthens: Report

    Global temperatures hit record highs as El Niño strengthens: Report

    Ant International, Mastercard and Visa Initiate Collaboration on Know-Your-Agent Interoperability to Scale Agentic Commerce

    County Championship: Gloucestershire’s Will Williams takes six wickets against Lancashire

    County Championship: Gloucestershire’s Will Williams takes six wickets against Lancashire

    The incomplete history of Duo devices

    The incomplete history of Duo devices