Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

https://image.theregister.com/5295408.jpg?imageId=5295408&x=0&y=14.72&cropw=100&croph=71.67&panox=0&panoy=14.72&panow=100&panoh=71.67&width=1200&height=683

At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia.

Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. “In terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted," he said. "However, the true number is almost certainly higher than this.”

Proofpoint’s threat hunters spotted the new kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew they track as TA412, also known as Violet Typhoon and APT31, used BlueMoon to “repeatedly” target non-governmental organizations (NGOs), mining companies, and physical...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE