4 groups caught using the same Chrome and Windows exploit kit
Ars Technica Dan Goodin
Four hacking groups are using the same Chrome-and-Windows exploit kit. It chains three bugs, and the patches only landed in the last 24 hours.
Based on reporting by Ars Technica, Dan Goodin — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Proofpoint says at least four hacking groups are actively using the same exploit kit against Chromium-based browsers and older Windows releases. The researchers call it BlueMoon, and it does not rely on one weakness. It chains three vulnerabilities together so an attacker can get code running and then install malware of their choosing.
Two of the bugs are in Chromium, and the third hits the kernel in Windows 10 Oct 2018 Update, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three have now been patched, but the timing matters: Proofpoint said the vulnerabilities were being used while fixes were only just becoming available.
The campaign also stands out for being noisy rather than careful. That is unusual. Attackers often keep newly found bugs under wraps and use them sparingly so the exploit stays useful for longer. Here, the same kit seems to have been shared widely enough that multiple groups picked it up.
Some of those groups have ties to the Chinese government, according to Proofpoint. The researchers think the broad use may have been helped by a patch gap in the Chromium supply chain, where a fix exists before it makes its way into browsers like Chrome and Edge. They also pointed to AI as another possible accelerant, since it can help spot vulnerabilities faster than humans working alone.
My take — AI-written commentary, not fact-checked reporting
This is what happens when exploit code gets industrialized: the same kit spreads, the same bugs get burned, and everybody pretends the mess was a surprise. The real problem isn’t just the holes in Chromium and Windows; it’s how quickly useful attack code gets shared once someone proves it works. Security folks can keep calling that a “trend,” but it’s mostly just the internet’s ugliest group project.
Read more about this at: Ars Technica
Related stories
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Ars Technica · 1 day ago ·
32
Google confirms Gemini models hacked three companies in May 2026
Ars Technica · 17 hours ago ·
14