Four Espionage Groups Caught Using Identical 'BlueMoon' Exploit Kit
A shared toolkit targeting U.S. defense contractors and Southeast Asian governments reveals a centralized supply chain for state-sponsored cyber-attacks.
At least four cyber-espionage groups, primarily linked to China, have been identified using an identical exploit kit dubbed "BlueMoon" to target high-value targets. The discovery reveals a sophisticated operation targeting U.S. defense contractors, NGOs, and government agencies across Southeast Asia, including Singapore, Indonesia, and Vietnam.
The BlueMoon kit gains full system control by chaining two Chromium vulnerabilities—including CVE-2026-85046—with a Windows kernel vulnerability. The flaw affects Windows 10 and Windows 11, including the operating system's initial release. Security researchers identified the kit in the operations of four distinct groups: TA412 (also known as APT31), UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket.
The Patch Gap
The attacks were made possible by a critical "patch gap," a window of time where a security fix is published in the Chromium open-source project but has not yet been integrated into the stable version of the Google Chrome browser. In this instance, attackers reverse-engineered the public open-source fix to weaponize the vulnerability before the general public received the update.
In a direct response to this vulnerability window, Google has accelerated the Chrome release cycle to two weeks. This move is intended to shrink the time between the discovery of a flaw and the deployment of a stable patch, reducing the opportunity for threat actors to exploit the gap.
A Centralized Supply Chain
The most striking aspect of the BlueMoon kit is the uniformity of the code across the four different hacking groups. According to Mark Kelly, a threat researcher at Proofpoint, the code is practically identical, extending even to the variable naming and internal commentary. Kelly stated, "There’s no way that this is parallel development... It’s the same kit. One hundred percent."
This level of consistency suggests that these separate espionage groups are not developing their own tools independently. Instead, they are likely utilizing a shared developer or a centralized, state-supplied supply chain. This indicates a highly organized infrastructure where high-end offensive tools are developed by a central entity or contractor and then distributed to various operational teams.
Industry Implications
This incident highlights a shift in the threat landscape where the window for exploiting "patch-gap" vulnerabilities is shrinking, partly due to the speed at which attackers can now analyze and weaponize public fixes. The use of a shared toolkit across multiple APT groups suggests that state-sponsored actors are increasingly relying on professionalized software development lifecycles for their malware.
Security teams are now urged to monitor for the specific indicators of the BlueMoon kit and ensure that browser updates are applied immediately upon release. While Google has shortened its update cycle, the incident serves as a reminder that the time between a vulnerability's public disclosure in open-source repositories and its weaponization is nearly instantaneous.