Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links which silently exploited the browser and installed malware. The activity targeted NGOs and commercial firms as well as government and finance organizations across several countries.
How the attack worked
Researchers observed four separate espionage groups using the same Chrome and Windows exploit kit, referred to as BlueMoon, within about a two week window. Each group relied on phishing emails built around believable business or academic pretexts rather than obvious malicious content. One cluster, TA412, posed as university students seeking internships or as outreach tied to an academic conference. A second cluster, UNK_LateNight, sent fake RFQ and procurement inquiry emails to aerospace and defense companies. A third cluster, UNK_DoubleCheck, used a compromised government email account to send a vaccination appointment lure to a manufacturing company.
In each case, the goal was the same: get the recipient to click a link. Once clicked, the exploit kit ran silently in the background while the browser redirected to a legitimate looking site, making the compromise difficult to notice in the moment.
Why it succeeded
The lures worked because they matched normal business and personal expectations. An internship request, a procurement inquiry, or a vaccination reminder are all plausible emails that many staff receive routinely. None of them look overtly suspicious on their own, and the redirect to a legitimate site after clicking removed the usual visual cue that something went wrong. This combination of believable pretext and clean-looking technical behavior let the exploit run before anyone had reason to suspect an issue.
What to watch for
- Unsolicited emails referencing internships, academic conferences, RFQs, or procurement requests that push a link click
- Vaccination or appointment-themed emails, especially from government-linked addresses, that ask for a click to confirm details
- Any link click that ends in a fast redirect to a legitimate site, since this can mask exploitation happening in the background
- Browser extensions branded as AI assistants, since one payload observed in this activity masqueraded as an AI-powered browsing companion
Building resistance
Organizations across NGOs, mining, commodity trading, aerospace and defense, manufacturing, government, consulting, and financial services were all represented in the affected industries here, showing how broadly these pretexts can be reused. Staff in procurement, finance, sales, HR, and executive assistant roles should verify unexpected internship, RFQ, or appointment requests through a separate trusted channel before clicking any link. Security teams should also treat vendor guidance about actively exploited zero-days as urgent, particularly for browsers and Windows systems on older builds, since the privilege escalation piece of this chain was patched as an actively exploited flaw in a recent Patch Tuesday release. Reinforcing awareness around unexpected link clicks and unfamiliar browser extensions can reduce the chance that a single click leads to silent compromise.
Key findings
- Four espionage groups adopted the same Chrome+Windows exploit kit (“BlueMoon”) within roughly two weeks.
- Initial access commonly started with phishing emails that used believable business/academic pretexts (internships, conferences, RFQs, vaccination appointments).
- Victims who clicked links were exploited “silently,” then redirected to a legitimate site while exploitation continued in the background.
- One observed payload masqueraded as a benign “AI-powered browsing companion by Google Gemini” browser extension (GemStone).
- Another cluster used fake RFQ/procurement emails to target aerospace/defense, delivering ShadowPad via a DLL sideloading chain and creating a scheduled task for persistence.
- The Windows local privilege escalation component targeted older Windows builds and was patched as an actively exploited zero-day in September 2026 Patch Tuesday.
Who’s being targeted
- Commonly targeted roles: All employees, Procurement, Finance, Sales, HR, Executive assistants, Government staff, Consultants, Security awareness trainees using Chrome/Chromium-based browsers.
- Affected industries: Non-profits/NGOs, Mining, Physical commodity trading, Aerospace and defense, Manufacturing, Government, Consulting, Financial services.
- Attack channels: email, website.
- Impersonated: University student / academic conference outreach, Potential customer / procurement contact, Southeast Asian government email account (compromised).
Red flags to watch for
- Unexpected unsolicited outreach with a link
- Link click results in a quick redirect to a legitimate site (possible masking behavior)
- Message creates urgency or pressure to respond about an internship/conference quickly
- Unexpected RFQ from an unknown sender
- Pressure to open a link rather than using normal vendor portals
- Email language or sender domain does not match known procurement processes
- Sender appears authoritative (government) but request is unexpected
- Appointment/health-themed lure pushes a link click
- Mismatch between recipient’s location/context and the supposed appointment
Frequently asked questions
What is BlueMoon in this attack?
BlueMoon is the name given to a Chrome plus Windows exploit kit that four separate espionage groups adopted within roughly two weeks of each other.
How did victims get exposed to the exploit?
Victims received phishing emails with believable pretexts like internship requests, conference outreach, RFQ inquiries, or vaccination appointments. Clicking the included link silently triggered exploitation while the browser redirected to a legitimate site.
What should employees watch for after clicking a suspicious link?
A quick redirect to a legitimate-looking site after a link click can mask background exploitation, so that behavior itself should be treated as a red flag.
Why does patching matter here?
The Windows privilege escalation component used in this chain targeted older builds and was patched as an actively exploited zero-day in the September 2026 Patch Tuesday, so applying that update is urgent.
Read the video transcript
You get an email: "Subject: Internship inquiry – Association for Asian Studies outreach." Looks legit, right? Behind that click is BlueMoon, a Chrome plus Windows exploit kit. It silently hits your browser, then bounces you to a real university site while malware installs in the background. Same trick hits procurement: "Subject: RFQ – request for pricing and availability." Click, quick redirect, then a fake "AI-powered browsing companion by Google Gemini" extension called GemStone quietly lands on your machine. If an unexpected internship, conference, or RFQ email wants you to click a link, stop. Don’t click, forward it to security and confirm through your usual channel instead.