Start your day with intelligence. Get The OODA Daily Pulse.
At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday. The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware against U.S. defense contractors, NGOs and Southeast Asian government agencies. Two additional groups are also believed to have used the kit, according to Proofpoint’s researchers, who said they expected further reporting on the campaign from other security companies. The episode fits a recurring pattern in which otherwise separate China-linked hackers gain access to the same offensive tooling at about the same time — raising questions about whether these groups are being supplied by the government or a shared contractor, or if the tools are being sold to multiple threat actors by a broader commercial market.