bleeping-computer · Crawled Sep 10, 2026
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
1 Actors 1 Malware 1 CVEs
Read original article ↗
AI Summary
A new exploit kit named 'BlueMoon' has been observed in the wild, leveraging chained zero-day vulnerabilities in Google Chrome and Microsoft Windows to achieve remote code execution and privilege escalation. The kit has been used by multiple cyber-espionage groups, including JungleBamboo (APT31) and UTA0560, in targeted attacks against NGOs, aerospace, defense, and manufacturing sectors. BlueMoon exploits three specific flaws: two in Chrome's V8 engine and one in Windows ALPC, enabling sandbox escape and local privilege escalation. The attacks are delivered via spearphishing, with payloads including malware loaders and in-memory backdoors such as Grimwedge and ShadowPad.
AI-extracted · verify before operational use
Extracted Entities 3 found
MITRE ATT&CK TTPs 33 techniques
T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1057 Process Discovery · Discovery T1090 Proxy · Command And Control T1124 System Time Discovery · Discovery T1071 Application Layer Protocol · Command And Control T1189 Drive-by Compromise · Initial Access