NewsTradingSentimentCalendarCommunityBriefing
World

Shared Chrome Exploit Links Multiple Chinese Cyber Groups

By Geopolitics Desk · 2026-09-09 · Updated 2026-09-10 01:41 UTC
A complex digital network of interconnected nodes and data streams
Illustration: Tradingbird

Proofpoint has revealed that multiple Chinese state-sponsored groups, including APT31 and UNK_LateNight, are deploying a shared exploit kit called BlueMoon that leverages unpatched Chrome and Windows vulnerabilities to install a credential-stealing backdoor masquerading as a Google Gemini extension.

  • New details from GN geopolitics/cyber (en-US) identify the shared tooling as an exploit kit named BlueMoon, which chains Chrome V8 flaws with a Windows ALPC bug to bypass sandboxes. The report notes that while APT31 was the first observed user, other China-linked clusters like UNK_LateNight have recently adopted the same kit to deploy a malware backdoor disguised as a Google Gemini extension.

    Source: GN geopolitics/cyber (en-US)
  • At least four state-linked hacking groups are using the same browser vulnerability, revealing a concerning trend in shared offensive tooling.

    Source: GN geopolitics/cyber (en-US)
Based on reporting by GN geopolitics/cyber (en-US), The Hacker News and GN geopolitics/cyber (en-US), compiled by the Tradingbird desk.

Read next

More in World

More from the World desk

All desk stories