THREATOPS
THREAT OPSThreat News › Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

medthehackernewsPublished 2026-09-09

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.

The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

Attributed threat actors

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html