Shared Chrome Exploit Links Multiple Chinese Cyber Groups

Proofpoint has revealed that multiple Chinese state-sponsored groups, including APT31 and UNK_LateNight, are deploying a shared exploit kit called BlueMoon that leverages unpatched Chrome and Windows vulnerabilities to install a credential-stealing backdoor masquerading as a Google Gemini extension.
New details from GN geopolitics/cyber (en-US) identify the shared tooling as an exploit kit named BlueMoon, which chains Chrome V8 flaws with a Windows ALPC bug to bypass sandboxes. The report notes that while APT31 was the first observed user, other China-linked clusters like UNK_LateNight have recently adopted the same kit to deploy a malware backdoor disguised as a Google Gemini extension.
Source: GN geopolitics/cyber (en-US)At least four state-linked hacking groups are using the same browser vulnerability, revealing a concerning trend in shared offensive tooling.
Source: GN geopolitics/cyber (en-US)






