Four espionage groups shared one Chrome exploit kit

Published

Four separate espionage groups reached for the same exploit chain against Chrome on Windows within days of one another. Researchers at Proofpoint documented the shared toolset and named it BlueMoon, and the timing is the part worth sitting with: every flaw in the chain had only just been fixed.

The attacks started with phishing email. A victim who clicked the link landed on a page built to exploit two vulnerabilities in V8, the engine that runs JavaScript inside Chrome, and then a Windows vulnerability that broke out of the browser's sandbox and lifted the attacker's privileges on the machine. The sandbox is the wall Chrome puts between a web page and the rest of the computer, so the third bug is what turns a bad web page into a foothold on a PC.

The patches were days old, not months

The two Chrome flaws were fixed in the stable channel on 3 and 8 September 2026, and the first was already being exploited when Google shipped its update. Microsoft addressed the Windows flaw in its September Patch Tuesday release, by which point that one was under attack too. CISA has since added all three to its Known Exploited Vulnerabilities catalog. IntelFusions covered both Chrome releases as they landed, the 3 September fix for a V8 flaw already used in attacks and the Chrome 153 update on 8 September that closed 230 bugs including one under exploitation.

What makes BlueMoon notable is not that it exploited freshly patched bugs. It is how fast the capability spread between groups that do not otherwise share tooling. Publicly visible upstream fixes can hand attackers clues before a downstream browser update reaches users, which leaves a window where a weaponised chain can be built and passed around while most machines are still unpatched. As the write-up puts it, some criminals are effectively beta-testing the patches on everyone else's behalf.

An AI angle that stops short of a claim

The researchers also found clues, but no conclusive evidence, that the kit itself was developed with AI assistance. That hedge should stay a hedge. The underlying worry is credible enough on its own terms, since language models are genuinely useful for reading source-code changes, adapting exploit code and working through failed attempts, but clues are not attribution.

Shrink the gap, starting with the KEV list

Not every update needs installing the moment it appears, and in an enterprise a browser or operating-system patch reasonably goes through testing and staged deployment. Vulnerabilities already known to be exploited are the exception, and that is precisely what CISA's KEV catalog is for: it tells you which handful to move on first. For everyone else the advice is duller. Install browser and operating-system updates when they are offered rather than postponing them, restart the browser so the update actually takes effect, and treat links in unsolicited mail as the delivery mechanism they were here.

Proofpoint's own report carries the technical detail on the chain; the summary we worked from is Malwarebytes' write-up of that research. Neither names the four groups involved.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions