โŒ

Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Register

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

9 September 2026 at 18:28
At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. โ€œIn terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted," he said. "However, the true number is almost certainly higher than this.โ€ Proofpointโ€™s threat hunters spotted the new kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew they track as TA412, also known as Violet Typhoon and APT31, used BlueMoon to โ€œrepeatedlyโ€ target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US. TA412 is a cyberespionage group linked by US authorities to China's Ministry of State Security (MSS), and American prosecutors previously charged seven alleged members with conspiracy to commit computer intrusions and wire fraud, alleging they broke into computer networks, email accounts, and cloud storage belonging to numerous critical infrastructure organizations, companies, and individuals. Just days after Proofpoint documented the late-August activity, โ€œseveral other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus,โ€ Kelly and fellow researchers Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said on Wednesday, noting that there may be other, non-China-nexus attackers using the exploit kit as well. โ€œBlueMoon was developed and deployed rapidly, and shared across multiple threat actors within days,โ€ Kelly told The Register. โ€œThis may reflect a reduced cost and barrier to entry for this class of capability, which has historically been rare and high value, as AI agents increasingly enable threat actor exploit development. That is particularly true for open-source codebases such as Chromium, where publicly accessible upstream patches create a โ€˜patch-gapโ€™ window for rapid reverse engineering and exploit development ahead of downstream stable releases.โ€ A Google spokesperson declined to comment beyond what Proofpoint wrote. Microsoft patched the Windows bug (CVE-2026-85880) on Tuesday, and a spokesperson reiterated that customers who applied that patch are protected. BlueMoon attack chain The kit chains together three vulnerabilities. The first is a V8 type confusion (CVE-2026-85046) flaw that allows remote code execution and affects all Chromium-based browsers, including Google Chrome and Microsoft Edge. Google patched this bug in Chrome on September 3, and at the time warned that it โ€œis aware that an exploit for CVE-2026-85046 exists in the wild.โ€ Microsoft published a security advisory saying it fixed the flaw in Edge Stable version 152.0.4191.62 on September 2. The second is a Chrome V8 sandbox escape. This one also affected all Chromium-based browsers. It does not have a CVE because Google doesnโ€™t issue them for sandbox escapes. Finally, the third bug is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880) that Microsoft patched on Tuesday, as noted above. Redmond also warned that this flaw had been exploited as a zero-day prior to the security update. The Proofpoint researchers also note that both V8 vulnerabilities are whatโ€™s called "patch-gap" zero-days at the time of the observed activity. This means they were known and fixed in upstream Chromium source code โ€“ a change containing the fix for CVE-2026-85046 was committed on August 7. But they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public for weeks. โ€œIt is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain,โ€ the researchers note. From phishing to browser surveillance The attacks start with a phishing email that tricks victims into clicking on an actor-controlled URL. This triggers the two V8 bugs to allow remote code execution and escape the browser sandbox. The attack chain then exploits the Windows bug to download multiple payloads including browser-surveillance malware, credential-stealing backdoors, and others, depending on the group using the exploit kit. TA412โ€™s first campaign, which began on August 28, used a range of lures. Some of the emails purported to come from university students interested in internships at the targeted organizations, and some were more target-specific exchanges, intended to build trust with the individual before ultimately sending a malicious link via email. In these instances, the exploit chain โ€œultimately downloaded and ran a loader executable on the infected host, which then installed a malicious browser extension disguised as Google Gemini on the victim's Chromium-based browser,โ€ the team wrote. This browser extension, which Proofpoint tracks as GemStone, allowed the Beijing spies to issue commands through a command-and-control (C&C) channel, steal cookies and other sensitive data, take screenshots, and inject a keylogger into a browser tab. The malware also contains a keyword monitor, which injects an attacker-specified keyword list into the top frame of each page, scans the HTML body for these keywords, and triggers a screenshot if it finds any. A few days later, beginning on September 2, a second China-aligned spy crew that Proofpoint tracks under the temporary group designator UNK_LateNight used BlueMoon to target multiple US aerospace companies. The phishing emails used request-for-quotation lures specific to defense industry organizations, and included links to attacker-controlled domains spoofing a variety of US aerospace companies. These websites also served the BlueMoon exploit kit and ultimately loaded a backdoor called ShadowPad, which has been shared among multiple China-aligned groups since 2019. Around this same time, on September 2, another suspected espionage group that Proofpoint tracks as UNK_DoubleCheck targeted a Vietnamese manufacturing firm with messages sent from a compromised Southeast Asian government email address. The fourth campaign began a day later, and involved suspected China-linked spy crew UNK_QuietRacket using BlueMoon to target government, consulting, and financial-sector organizations in Indonesia and Singapore. These phishing emails used lures related to Indonesian conferences, such as the Indo Startup Expo and Forum 2026 and the World Conference on Creative Economy (WCCE 2026). Proofpoint warns that BlueMoon will likely be used by both cyberspies and financially motivated attackers. โ€œThe broader dynamic revealed by this activity - rapid exploit development that leverages the open source patch-gap โ€“ is likely to recur beyond BlueMoon as this development model becomes accessible,โ€ the team wrote. ยฎ

Extortion crews have their eyes on high-value AI data, Google warns

8 September 2026 at 08:00
Data theft and extortion crews are stealing companiesโ€™ proprietary AI data and threatening to leak it if the victim organizations donโ€™t pay a ransom, according to Googleโ€™s threat hunters. In one case that Googleโ€™s Mandiant incident response team investigated, the crooks broke into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company met their extortion demand. In another breach at a company that specializes in AI media generation, attackers stole sensitive AI data including source code, prompts, skills, model scripts, and secrets before demanding a payment and threatening to dump the AI assets publicly if the ransom wasnโ€™t paid. Google detailed these two intrusions for the first time in its most recent AI Threat Tracker, published Tuesday and shared in advance with The Register. โ€œBut it's certainly not limited to that,โ€ John Hultquist, chief analyst at Google Threat Intelligence Group, said in an interview with The Register. Mandiant responded to several of these data-theft-and-extortion operations during the second quarter of 2026, he said. The intrusions affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors in North America and Europe. โ€œItโ€™s become a really valuable target where organizations are spending a lot of money and investment, and they don't necessarily want their IP exposed to the open world, so they're willing to pay in an extortion scheme,โ€ Hultquist said. โ€œCriminals attacking AI systems is an area that's not received as much attention as it probably should, and as we incorporate these systems, itโ€™s going to come with brand-new risks,โ€ Hultquist added. โ€œThere are certainly threat actors who are ahead of others when it comes to that problem โ€“ TeamPCP has been extremely successful.โ€ Since March, TeamPCP has pulled off several very large scale open source supply chain attacks targeting ecosystems including PyPI, npm, and Docker Hub. After compromising these open source packages and registries, TeamPCP, which Google tracks as UNC6780, typically deploys stealers to scoop up cloud and AI system credentials. โ€œEvidence indicates that UNC6780 created a malicious GitHub Actions workflow for the companyโ€™s proprietary AI repository, and that the extortion actor exfiltrated a copy of this AI repository,โ€ the report says. โ€œBeyond these demonstrated tactics, UNC6780 has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices.โ€ While Googleโ€™s earlier AI tracker, published in February, documented attackers experimenting with agentic AI to support certain pieces of the attack chain, in the past quarter theyโ€™ve gone on to integrate agentic capabilities into multiple stages of an attack lifecycle, according to the researchers. In one example, Mandiant observed miscreants who compromised an organizationโ€™s cloud infrastructure in an autonomous, multi-agent credential-harvesting attack that took less than six hours. During that time, the agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP rotation logic without manual intervention. โ€œLike scanning โ€“ but with a brain,โ€ Hultquist said. In another case detailed in the report, Google Threat Intelligence observed a China-linked espionage group using Gemini to design a dynamic, automated penetration-testing framework that could reason through actions, execute tasks, and change course as needed in unpredictable environments. Google disabled the assets associated with this particular crew. โ€œThatโ€™s where we are headed,โ€ Hultquist said. โ€œWe're kind of in this interim place where threat actors are inserting agentic AI into certain parts of their operations, but we've not gotten to the place where they are able to sort of remove themselves entirely. We're right on the precipice of that.โ€ ยฎ

โŒ
โŒ