Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure9 September 2026, Wednesday

BlueMoon exploit kit: Chrome and Windows zero-day vulnerabilities spread rapidly among China-aligned groups

Proofpoint identified four threat clusters; targets include US aviation companies and government and financial institutions in Indonesia and Singapore.

SINGAPORE

According to a Proofpoint report dated 9 September, the BlueMoon exploit kit, first observed on 28 August, compromises systems by chaining two Chrome V8 vulnerabilities with a Windows kernel vulnerability. The company identified four clusters using the kit, three of them aligned with China. TA412, also known as APT31, targeted US civil society, mining and commodity trading companies; UNK_LateNight targeted US aviation companies; and UNK_QuietRacket targeted government and financial institutions in Indonesia and Singapore.

According to a SecurityWeek report of 12 September, the kit was shared among different groups within a few days; one cluster hit the manufacturing sector in Vietnam. Although the incident involved no disruption or destruction, it shows that state-linked espionage capability can scale rapidly through zero-day vulnerabilities and that critical institutions in South-East Asia are also being targeted.

Talay assessment

Bottom line

BlueMoon spreading within days of its first sighting to four separate clusters, three of them China-aligned, shows state-linked groups rapidly sharing zero-day capability from a common pool. The activity is espionage-focused rather than destructive, so the main risk is data exfiltration that continues unnoticed. The most likely path is for patches to close the chain, while access to systems compromised before patching persists for some time.

Likely effects

  • Corporate cyber securityNegativeWeeks

    Exploiting Chrome and the Windows kernel together leaves organisations with patching delays exposed; aviation, commodity trading, government and financial institutions are the most at risk.

  • Turkish institutionsNegativeWeeks

    Türkiye is not among the targets in the report, but the same browser and operating system are widespread across Turkish public and financial institutions; those with weak patching discipline remain exposed to a similar chain.

  • Southeast Asian securityNegative1–6 months

    Government, finance and manufacturing targets in Indonesia, Singapore and Vietnam show the region becoming a priority theatre for state-backed espionage, increasing the need for institutional defence investment.

Possibilities, ranked

  1. 1
    Limited wave closed by patches50%

    Google and Microsoft patches are widely applied and new victim disclosures stay limited; cleaning up existing intrusions takes weeks.

    Watch: Patches released for the relevant Chrome and Windows flaws and no new post-patch exploitation reports

  2. 2
    Spread to more actors and regions40%

    The kit passes to other state-linked or criminal groups, and campaigns are detected in new sectors and countries.

    Watch: Reports from security firms identifying new clusters or new target countries

  3. 3
    Escalation into a diplomatic attribution row10%

    One of the targeted governments formally attributes the attacks to China and the incident becomes a bilateral diplomatic dispute.

    Watch: A formal attribution statement or sanctions step by an affected government

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Sources

  1. Proofpoint — Once in a BlueMoon: multiple state-aligned threat actors rapidly adopt novel exploit
  2. SecurityWeek — BlueMoon exploit kit chains recent Chrome, Windows zero-days