• Multiple hacking groups found using the same Chrome malware in th

    From TechnologyDaily@1337:1/100 to All on Thu Sep 10 16:15:20 2026
    Multiple hacking groups found using the same Chrome malware in the same week so what does it mean?

    Date:
    Thu, 10 Sep 2026 15:10:00 +0000

    Description:
    Someone is afraid of missing out, as defenders rush to patch things up.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Proofpoint detailed BlueMoon,
    an exploit kit chaining two Chromium flaws and one Windows bug Four groups, including Chinaaligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets Exploits were patchgap zerodays; all flaws now patched Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain fear of missing out among the criminals, experts have warned.

    Security researchers Proofpoint have detailed BlueMoon, an exploit kit that leverages three vulnerabilities: two in Chromium, and one in older versions
    of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11 . The kit
    was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States. Latest Videos From TechRadar Watch full video here:

    Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.

    What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited
    for longer. You may like Google patches multiple browser bugs including one that was under active exploitation so update now Microsoft's nemesis
    returns: Nightmare Eclipse is back with a new zero day A malware installer posing as a legitimate download service is infecting brands across almost every industry Microsoft Edge, Razer, Kaspersky and more actively imitated Front running the Chromium supply chain train BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a type confusion bug, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a sandbox escape flaw, for which Google did not assign
    a CVE or a severity score.

    The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a browser such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. No time to hide Both V8 vulnerabilities were patch-gap zero-days at the time of the observed activity, Proofpoint said. In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases
    of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.

    Another important factor is Artificial Intelligence. It would seem that AI
    has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly. What to read next This Russian cybercrime campaign can infect a user just by viewing an email Microsoft says it's hard at work on a patch for this worrying Defender zero-day A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call

    A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development, Proofpoint stressed.

    All three flaws have since been patched, so make sure youre running the
    latest version of both the OS and the Chromium browser.

    Via Ars Technica The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/multiple-hacking-groups-found-using-the -same-chrome-malware-in-the-same-week-so-what-does-it-mean


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)