4 groups caught using the same Chrome and Windows exploit kit

杂七杂八
4 groups caught using the same Chrome and Windows exploit kit
摘要

安全公司Proofpoint发现,至少四个黑客组织(部分与中国政府有关联)正在积极使用一个名为BlueMoon的漏洞利用工具包。该工具包针对Chromium内核浏览器及旧版Windows系统,将三个漏洞(两个Chromium漏洞和一个Windows内核漏洞)串联,以安装任意恶意软件。相关漏洞已在24小时内获得补丁。该攻击缺乏隐蔽性,被广泛使用。Proofpo

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Read full article

Comments

转载信息
原文: 4 groups caught using the same Chrome and Windows exploit kit (2026-09-09T20:55:02)
作者: Dan Goodin 分类: 科技
评论 (0)
登录 后发表评论

暂无评论,来留下第一条评论吧