Multiple espionage groups, including the China-aligned APT31 and several others suspected of Chinese links, rapidly adopted a previously undocumented exploit kit named BlueMoon within a week to target Windows and Chrome vulnerabilities. BlueMoon chains three vulnerabilities in Chrome's V8 engine and Windows ALPC to achieve code execution and privilege escalation, often delivered through spear-phishing and used to deploy malware via DLL sideloading and malicious Chrome extensions. Despite patches being released, organizations are urged to check for persistent artifacts like malicious browser extensions, scheduled tasks, and suspicious files, as the exploit kit's spread may continue due to its ease of adoption and possible AI-assisted development.
https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html

