Four espionage groups shared Chrome and Windows exploit kit
At least four cyberespionage groups, most assessed as China-aligned, used the same previously unknown exploit kit to attack Chrome browsers and Windows systems in campaigns that began in late August 2026, according to research published by the security firm Proofpoint. The kit, which Proofpoint tracks as BlueMoon, chains two vulnerabilities in Chromium's V8 JavaScript engine with a Windows privilege-escalation flaw, and was adopted by separate threat clusters within days of its first observed use. The first confirmed use came on August 28, 2026, from TA412, a China-nexus actor also known as APT31 or Violet Typhoon that US authorities indicted in 2024. TA412 targeted US nongovernmental organizations, mining companies, and commodity trading firms with phishing lures posing as university internship inquiries and academic conference outreach, ultimately installing a malicious browser extension disguised as Google's Gemini AI assistant that Proofpoint tracks as GemStone.