Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday.
The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware against U.S. defense contractors, NGOs and Southeast Asian government agencies.
Two additional groups are also believed to have used the kit, according to Proofpoint’s researchers, who said they expected further reporting on the campaign from other security companies.
Source: https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
Related breach coverage
- One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire2026-09-15
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]
- Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days2026-09-10
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]
- China-linked Fire Ant Hides Inside Trusted Infrastructure2026-08-31
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising […]
- Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics2026-08-21
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]