
Four Espionage Groups Deploy BlueMoon Exploit Kit Chaining Windows and Chrome Vulnerabilities
Multiple espionage-motivated threat activity clusters have been observed deploying a previously undocumented exploit kit named BlueMoon. The kit chains together multiple vulnerabilities in Microsoft Windows and Google Chrome to gain initial access for in-the-wild espionage operations. Four distinct threat groups were observed using the kit within a single week, marking a significant concentration of coordinated activity. The first attributed use has been linked to APT31, a China-aligned state-sponsored group, with additional clusters also identified. No specific victim counts or data exfiltration details have been disclosed.