hacker-news · Crawled Sep 10, 2026

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

11 IoCs 1 Actors 1 Malware 1 CVEs
Read original article ↗

AI Summary

Multiple espionage-motivated threat actors, including APT31 and several China-aligned clusters, have leveraged a previously undocumented exploit kit named BlueMoon to exploit unpatched vulnerabilities in Google Chrome and Microsoft Windows. The exploit chain combines CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to achieve sandbox escape and local privilege escalation, delivered via phishing emails leading to malicious URLs. The kit downloads payloads such as the GemStone browser backdoor, ShadowPad, and Rust-based malware using DLL sideloading and in-memory execution techniques. The U.S. CISA has added all three CVEs to its KEV catalog, mandating federal agencies to patch them by mid-September 2026.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 11 extracted

Type Value Detail
Filename ChromeUpdate.exe Details →
Filename msgbox.exe Details →
Filename curl.exe Details →
Filename cmd.exe Details →
Filename GeForceService Details →
Filename EdgeCore_AutoUpdate Details →
Filename MicrosoftEdgeUpdatesTaskMachine Details →
Filename Avpcheckup Details →
Filename Dataupcheckinfo Details →
Filename C:\Users\Public\stomp_ext Details →
Registry User HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32 Details →

MITRE ATT&CK TTPs 33 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1057 Process Discovery · Discovery T1090 Proxy · Command And Control T1124 System Time Discovery · Discovery T1071 Application Layer Protocol · Command And Control T1189 Drive-by Compromise · Initial Access