Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using th 2026-9-9 17:4:43 Author: therecord.media(查看原文) 阅读量:9 收藏

At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday.

The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware against U.S. defense contractors, NGOs and Southeast Asian government agencies.

Two additional groups are also believed to have used the kit, according to Proofpoint’s researchers, who said they expected further reporting on the campaign from other security companies.

The episode fits a recurring pattern in which otherwise separate China-linked hackers gain access to the same offensive tooling at about the same time — raising questions about whether these groups are being supplied by the government or a shared contractor, or if the tools are being sold to multiple threat actors by a broader commercial market.

Proofpoint said the hackers were separate groups conducting separate operations — they pursued different targets and used their own malware and command-and-control infrastructure — but the exploit kit was definitely shared between them.

“There’s no way that this is parallel development,” Mark Kelly, a threat researcher at Proofpoint, said in an interview with Recorded Future News. “The code is practically identical — even the variable naming, the commentary. It’s the same kit. One hundred percent.”

Without a dream in my heart

BlueMoon exploited an underlying vulnerability that had actually been fixed in Chromium — the open-source project that Chrome is built on — in early August. But the changes to Chromium’s public code took four weeks before reaching people using the stable version of the Chrome web browser.

That created what researchers call a patch gap, a period during which attackers can study the public code, identify the fix and try to work out what vulnerability it addressed in order to build an exploit before the fix reaches users.

“Historically, that [four-week gap] has been pretty reasonable,” Kelly said, noting that reverse-engineering and weaponizing a patch within that period had been rare. “That seems to no longer be the case.”

Google on Tuesday began moving Chrome to a two-week release cycle, partially to get security fixes to users faster.

The BlueMoon exploit kit combines two browser flaws with a Windows vulnerability allowing attackers to take control of a victim’s computer. The kit then hands off to malware chosen by whichever group is using it.

Proofpoint said that this final step is surprisingly crude, using the common curl command-line tool to download a malicious file into a temporary folder — actions that give security software multiple opportunities to detect the attack.

Kelly said that sloppiness likely reflected the race to use the exploit before Chrome users received the patch.

“Because of the patch-gap dynamic, where there was a patch incoming, it seemed like that shifted much more towards getting this thing out as quickly as possible,” he said.

That rush has appeared in previous China-linked campaigns. Western analysts assess that many Chinese hacking groups operate independently, yet a pattern has emerged of these groups repeatedly exploiting the same bugs just as patches were released.

Read more: Three hacking groups, two vulnerabilities and all eyes on China

The first group Proofpoint observed using the exploit kit, TA412 — also tracked as APT31, Violet Typhoon and RedBravo — began doing so at the end of August.

U.S. authorities indicted a number of Chinese individuals accused of working for this group in 2024, and sanctioned a Wuhan-based company associated with its attacks on critical infrastructure and believed to be a front for China’s Ministry of State Security.

Proofpoint said this group targeted U.S. NGOs, mining companies and commodity traders using lures including fake internship inquiries and messages about an Asian Studies conference.

It installed a malicious browser extension disguised as Google’s Gemini AI assistant that “functions as a browser-surveillance and credential-theft backdoor.”

A second group, tracked as UNK_LateNight, then used BlueMoon to target U.S. aerospace and defense companies with fake procurement inquiries and installed ShadowPad, a backdoor widely used by Chinese state hackers.

A third group, tracked as UNK_DoubleCheck, began using BlueMoon at the same time as LateNight. It targeted a Vietnamese manufacturer using a compromised Southeast Asian government email account and a fake vaccination appointment.

Proofpoint said it has not attributed the group to any country. Kelly said: “We just haven’t necessarily attributed [them] yet. We’re not saying they are not China-aligned.”

The fourth group, UNK_QuietRacket, targeted government, consulting and financial organizations in Indonesia and Singapore with fake Indonesian conference invitations. Proofpoint assessed it as suspected China-aligned.

Hackers using AI

The company also found signs that AI may have helped develop BlueMoon, including debugging comments resembling exchanges with an AI tool and references to a document used to carry context between AI sessions.

Kelly said AI may be making it easier to turn public software fixes into working exploits before patches reach users.

“People on Twitter are reverse-engineering these Chromium patches to develop working exploits using AI,” he said. “It’s pretty good at it, because it’s open-source code.”

The code also referenced Google’s V8 bug-bounty challenge, suggesting the developers may have presented the work to an AI system as legitimate security research while building the exploit.

How the separate groups obtained the same exploit within days remains unclear.

One possibility is the model seen with ShadowPad; a private developer builds a tool and sells it to multiple state customers. Proofpoint could not determine whether BlueMoon came from a common contractor, was distributed by the state or spread through another shared channel. “It’s such a tangled web,” Kelly said. “It’s very difficult to unpick.”

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79


文章来源: https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
如有侵权请联系:admin#unsafe.sh