discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Four spy groups used the same Chrome and Windows exploit kit within a week, with APT31 being the first in-the-wild use attributed to China-aligned actors.

By Ravie Lakshmanan·Sep 9·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Image: thehackernews.com

Multiple espionage groups have started using a new exploit kit called BlueMoon, which combines vulnerabilities in Chrome and Windows. APT31 was the first to use it in the wild.

Why it matters

This highlights the ongoing threat of exploit kits and the need for timely patching and security measures.

Some bad guys used a new trick to trick people into giving them their computer's password. They did it with a special program that uses two different bugs to do it. The first group to do it was from China, and they tricked people who work with money and things.

Analysis

{"

BlueMoon Exploit Kit Overview":"BlueMoon is a new exploit kit that combines vulnerabilities in Google Chrome and Microsoft Windows. It has been used by multiple espionage groups within a week.","

APT31's Use of BlueMoon":"APT31, a China-aligned state-sponsored group, was the first to use BlueMoon in the wild on August 28, 2026. They targeted NGOs, mining companies, and commodity trading firms in the U.S. with spear-phishing lures.","

UNK_LateNight's Use of BlueMoon":"UNK_LateNight, another China-aligned group, used BlueMoon to target U.S. aerospace companies. They deployed the ShadowPad backdoor using DLL sideloading.","

UNK_DoubleCheck's Use of BlueMoon":"UNK_DoubleCheck used BlueMoon to target a Vietnamese manufacturing entity. They used a Cloudflare Workers domain to download and execute a second DLL sideloading pair.","

UNK_QuietRacket's Use of BlueMoon":"UNK_QuietRacket used BlueMoon to target government, consulting, and financial sector organizations in Indonesia and Singapore. They modified the exploit kit to download and execute a DLL sideloading pair."}

Key points

  • Multiple espionage groups used BlueMoon within a week
  • APT31 was the first to use BlueMoon in the wild
  • BlueMoon combines vulnerabilities in Chrome and Windows
  • The exploit kit uses phishing emails to trick people
  • The bad guys use different methods to hide their actions
The Upside

Timely updates and security patches can help stop these bad guys from using their trick.

The Downside

The bad guys might find new tricks to use, so we need to keep learning about computer security.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagemalwareexploit-kitchina

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 9, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagemalwareexploit-kitchina

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.