Skip to content
theregister·

🚨BlueMoon Exploit Kit Targets NGOs and Firms with China Links

New exploit kit targets NGOs and firms with suspected China ties

TL;DR

BlueMoon, a new exploit kit, is being used by at least four espionage groups with suspected links to China to target NGOs, mining companies, and aerospace firms. The kit exploits three vulnerabilities in Chromium-based browsers and Windows.

BlueMoon, a new exploit kit, is being used by at least four espionage groups with suspected links to China to target NGOs, mining companies, and aerospace firms. The kit exploits three vulnerabilities: a V8 type confusion flaw, a Chrome V8 sandbox escape, and a privilege escalation vulnerability in Windows. If you use Chromium-based browsers or Windows, this is a big deal. The V8 type confusion flaw was patched in Chrome on September 3, but the kit was first observed on August 28. The Windows privilege escalation vulnerability was patched on Tuesday. The exploit kit is used to download multiple payloads, including browser-surveillance malware and credential-stealing backdoors. The malware allows attackers to issue commands through a C&C channel, steal cookies and other sensitive data, take screenshots, and inject a keylogger into a browser tab.

BlueMoon Exploit Kit Targets NGOs and Firms with China Links — theregister

Key Points

1

BlueMoon targets NGOs, mining companies, and aerospace firms with suspected China links.

2

The kit exploits three vulnerabilities: V8 type confusion flaw, Chrome V8 sandbox escape, and Windows privilege escalation.

3

V8 type confusion flaw patched in Chrome on September 3, but kit was first observed on August 28.

4

Windows privilege escalation vulnerability patched on Tuesday.

5

BlueMoon downloads multiple payloads, including browser-surveillance malware and credential-stealing backdoors.

Why It Matters

If you use Chromium-based browsers or Windows, BlueMoon is a significant threat. The kit exploits vulnerabilities in widely used software, making it a risk for organizations of all sizes. The malware allows attackers to steal sensitive data and monitor browser activity, posing a serious security risk.

BlueMoonexploit kitChina linksNGOsWindows

Frequently Asked Questions

Why does this matter?

If you use Chromium-based browsers or Windows, BlueMoon is a significant threat. The kit exploits vulnerabilities in widely used software, making it a risk for organizations of all sizes. The malware allows attackers to steal sensitive data and monitor browser activity, posing a serious security risk.

What happened?

BlueMoon, a new exploit kit, is being used by at least four espionage groups with suspected links to China to target NGOs, mining companies, and aerospace firms. The kit exploits three vulnerabilities in Chromium-based browsers and Windows.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,472 builders reading daily.

Also get