Proofpoint says four groups are sharing one Chrome exploit kit, and the patches landed in the last 24 hours

Why it mattersAnyone shipping a Chromium-based browser, Edge, or an Electron app needs to force the patch this week: the same three-bug chain is already in the hands of four separate groups.
Security firm Proofpoint said on Wednesday that at least four hacking groups have been running a nearly identical exploit kit against Chromium-based browsers and older versions of Windows, Ars Technica reports. Proofpoint calls the kit BlueMoon and says it chains three vulnerabilities together, giving whoever runs it a way to install malware of their choice. All three bugs received patches in the past 24 hours.
Two of the three flaws are in V8, Google's open source JavaScript engine used inside Chrome and every other Chromium browser. Attackers combined a V8 type confusion bug with a separate V8 sandbox escape to execute code, then chained a Windows kernel vulnerability to break out of the browser sandbox. The Windows bug affects the October 2018 update of Windows 10 and 11's initial release, alongside Windows Server 2019 and 2022.
The pace is what changed
A fully weaponised Chrome chain used to be a rare, high-value capability that a single group would use sparingly to keep it working longer. Proofpoint said BlueMoon looked nothing like that. It was developed, deployed and shared across multiple groups within days, in a way that produced high detection signals. The company points to two likely contributors.
The first is the Chromium patch gap. Chromium fixes are public in the upstream repository before Chrome, Edge and other downstream browsers ship a build that includes them, which creates a window where attackers can reverse a patch and build an exploit before most users receive it. The second, Proofpoint says, is AI. "This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development," the company wrote in its report, quoted by Ars.
Who was hit
Ars, quoting Proofpoint, names four groups. TA412, a China-aligned state-sponsored actor indicted by the US government in 2024, hit non-governmental organisations, mining companies and physical commodity trading firms in the US. UNK_LateNight, a second China-aligned espionage group, went after multiple US aerospace companies. UNK_DoubleCheck targeted a Vietnamese manufacturing entity. UNK_QuietRacket hit organisations in Singapore and Indonesia. The first campaign began on 28 August; the rest started earlier this month. Proofpoint says it does not know whether other groups also have the kit.
What to check today
Anyone running an Electron app, an embedded Chromium build, or Microsoft Edge on old Windows should force an update rather than trust a scheduled rollout. Server operators on Windows Server 2019 or 2022 need the Windows kernel patch on the same footing. The patch-gap point applies beyond this specific chain: a public upstream Chromium fix is now, on the evidence of BlueMoon, enough time for four groups to build against it. If your release train sits far behind an upstream security fix, that gap is a shipping decision, not a technical one.
Source
- Ars Technica: 4 groups caught using the same Chrome and Windows exploit kit, by Dan Goodin, 9 September 2026.
- Referenced: Proofpoint research on the BlueMoon kit.
Reported by: Ars Technica
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually shipping with them. Short, and only when there is something worth reading.


