Interestana
Home/News/Four Hacking Groups Use Identical Chrome, Windows Exploit Kit
Ars Technica2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Four Hacking Groups Use Identical Chrome, Windows Exploit Kit

Four Hacking Groups Use Identical Chrome, Windows Exploit Kit

At least four distinct hacking groups are actively employing an exploit kit that targets critical vulnerabilities in both Chromium-based web browsers and older versions of the Windows operating system. Security firm Proofpoint identified this exploit kit, which they have named BlueMoon, noting its near-identical nature across the observed campaigns. The BlueMoon kit chains together three specific vulnerabilities to enable attackers to deploy their chosen malware. Two of these vulnerabilities affect the Chromium browser engine, while the third targets the kernel of several Windows versions. Specifically, the affected Windows versions include the October 2018 Update for Windows 10, Windows Server 2019, Windows 10 version 2004, Windows Server 2022, and the initial release of Windows 11. Proofpoint reported that all three exploited vulnerabilities have been patched within the last 24 hours prior to their announcement. The deployment of the BlueMoon exploit kit was characterized by its rapid and widespread nature, lacking the typical stealth associated with many advanced hacking campaigns. Hackers often aim to use newly discovered vulnerabilities sparingly to prolong their effectiveness. Proofpoint suggests that the broad and visible use of this particular exploit chain may have been intended to capitalize on a "patch gap" within the Chromium supply chain. This gap refers to the period between when a vulnerability is patched by browser developers and when that patch is integrated into widely used browsers like Google Chrome and Microsoft Edge. The researchers also posited that the use of artificial intelligence could be a contributing factor to the rapid discovery and exploitation of these vulnerabilities, as AI can potentially identify security flaws more quickly than human-only methods. The involvement of some of these hacking groups with the Chinese government was also noted by Proofpoint, indicating a potential state-sponsored element to the observed attacks. The identification of a single, shared exploit kit across multiple distinct threat actors highlights the increasing sophistication and potential for resource sharing within the cybercriminal underground. This also underscores the ongoing challenge for organizations to defend against rapidly evolving exploit chains that leverage both browser and operating system vulnerabilities.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next