{"id":243847,"date":"2026-09-10T01:18:25","date_gmt":"2026-09-10T06:18:25","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/four-spy-groups-used-the-same-chrome-and-windows-exploit-kit-within-a-week"},"modified":"2026-09-10T01:18:25","modified_gmt":"2026-09-10T06:18:25","slug":"four-spy-groups-used-the-same-chrome-and-windows-exploit-kit-within-a-week","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/four-spy-groups-used-the-same-chrome-and-windows-exploit-kit-within-a-week","title":{"rendered":"Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/four-spy-groups-used-the-same-chrome-and-windows-exploit-kit-within-a-week.jpg\"><\/a><\/p>\n<p>Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called <strong>BlueMoon<\/strong> that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.<\/p>\n<p>The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as <a href=\"https:\/\/thehackernews.com\/2025\/11\/china-linked-apt31-launches-stealthy.html\" target=\"_blank\">APT31<\/a> (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.<\/p>\n<p>\u201cWithin days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus,\u201d Proofpoint <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit\" target=\"_blank\">said<\/a> in a report published today. \u201cHowever, BlueMoon may not be exclusive to China-aligned actors, as some usage remains unattributed and there are also potentially more actors using the exploit kit.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-243847","post","type-post","status-publish","format-standard","hentry","category-futurism"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=243847"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243847\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=243847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=243847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=243847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}