Proofpoint reported at least four espionage groups (mostly linked to Chinese state intelligence) using the same Chrome zero-day exploit kit (“BlueMoon”) to compromise victims and deliver malware. The operations used believable business and event-themed lures (internship inquiries, procurement requests, conference invites, and vaccination appointments), targeting U.S. defense contractors, NGOs, and government-related organizations in Southeast Asia.
How the attack worked
At least four separate cyber-espionage groups, mostly linked to Chinese state intelligence, were found using the same Chrome zero-day exploit kit, dubbed BlueMoon by Proofpoint. Rather than building separate exploit chains, the groups shared the same browser exploit and then deployed different malware depending on their objectives. This let multiple operations move quickly against a wide range of targets, including U.S. defense contractors, NGOs, and government-related organizations in Southeast Asia.
Each group used a business or event-themed lure tailored to its intended victims. These included fake internship inquiries, messages about an Asian Studies conference, procurement inquiries sent to aerospace and defense companies, and a fake vaccination appointment sent from a compromised Southeast Asian government email account. One operation went further after initial access, installing a browser extension disguised as Google's Gemini AI assistant that functioned as a browser-surveillance and credential-theft backdoor. Another used procurement-themed outreach to deliver ShadowPad, a backdoor associated with China-aligned activity.
Why it succeeded
The lures worked because they matched the professional context of the people receiving them. Procurement staff at defense and aerospace companies received what looked like ordinary requests for quotes. NGO program staff and researchers received internship and conference-related outreach that fit their normal correspondence. The vaccination appointment lure carried extra weight because it came from a compromised government email account, borrowing legitimacy from a real, trusted sender rather than a spoofed one.
The shared exploit kit also meant defenders faced a narrow window between a fix becoming available and attackers weaponizing it, a gap researchers described as no longer being rare.
What to watch for
- Unsolicited procurement, internship, or conference-related messages that push quick action
- Browser prompts asking to install or approve an extension you did not seek out
- Extension branding that imitates a known product, such as an AI assistant, without coming from an official source
- Appointment or administrative messages, even from apparently official senders, that request opening a link or file unexpectedly
How to build resistance
Organizations in procurement, HR, executive support, and NGO program roles should treat unsolicited business requests as higher risk and verify senders through a separate trusted channel before clicking links. Browser extensions should only come from approved corporate catalogs, with publishers confirmed as legitimate. Staff should also understand that even accounts belonging to known, trusted organizations can be compromised, so message content and context still matter. Finally, keeping browsers and endpoint protections updated as quickly as possible reduces the window attackers have to exploit newly disclosed flaws.
Key findings
- At least four cyber-espionage groups used the same shared exploit kit (“BlueMoon”) against Chrome, then delivered different malware depending on the group.
- Targets included “U.S. defense contractors, NGOs and Southeast Asian government agencies.”
- Lures included “fake internship inquiries,” “messages about an Asian Studies conference,” “fake procurement inquiries,” “a fake vaccination appointment,” and “fake Indonesian conference invitations.”
- One operation installed “a malicious browser extension disguised as Google’s Gemini AI assistant” that acted as “a browser-surveillance and credential-theft backdoor.”
- Another operation used procurement-themed outreach to deliver ShadowPad (a backdoor associated with China-aligned activity).
- One campaign used a “compromised Southeast Asian government email account,” increasing credibility.
- Proofpoint noted the final delivery step was “surprisingly crude,” using curl to download malware into a temp folder, likely due to time pressure before patches landed.
Who’s being targeted
- Commonly targeted roles: Procurement, Sales / Contracts / Proposals, HR / Recruiting, Executive assistants, NGO program staff, General staff (browser safety and extension installation).
- Affected industries: Defense industrial base / aerospace and defense, Nonprofits / NGOs, Government (Southeast Asia), Consulting, Financial services, Manufacturing.
- Attack channels: email.
- Impersonated: Conference organizer or student/recruiter (external contact), Procurement office / buyer from a prospective customer, Southeast Asian government agency (from a compromised account).
Red flags to watch for
- Unexpected outreach pushing you to click quickly (internship/professional event pitch you didn’t solicit)
- Browser prompts to add an extension that you didn’t go looking for
- Extension branding that imitates a well-known product (Gemini) but isn’t from an official source
- Unsolicited procurement request from an unknown sender
- Pressure to review a link/document immediately
- Sender details that don’t match a known customer/vendor relationship
- Appointment message you didn’t schedule or that doesn’t match local process
- Unexpected link/attachment even though the sender appears to be government
- Mismatch between the topic (vaccination) and your role/responsibilities
Frequently asked questions
What is the BlueMoon exploit kit?
BlueMoon is the name Proofpoint gave to a shared Chrome zero-day exploit kit used by at least four cyber-espionage groups to compromise browsers and deploy different malware.
Who was targeted in this campaign?
Targets included U.S. defense contractors, NGOs, and Southeast Asian government agencies, reached through lures like fake internship inquiries, procurement requests, and conference invitations.
How did the fake Gemini extension work?
One operation installed a malicious browser extension disguised as Google's Gemini AI assistant that functioned as a browser-surveillance and credential-theft backdoor.
Why did a compromised government email account matter?
A compromised Southeast Asian government email account was used to send a fake vaccination appointment lure, making the message appear more credible to the target.
Read the video transcript
You get an email: “Asian Studies conference, quick question.” Looks legit, even from a real .gov address. You click the link, and a Chrome window pops up asking to install a “Gemini AI assistant” extension. That’s BlueMoon at work, China-linked groups using a shared Chrome exploit kit to drop a fake Gemini that spies on your browser and steals credentials. Same trick hits defense and NGO staff with fake procurement RFQs too, open the link, Chrome gets exploited, and a backdoor like ShadowPad lands in a temp folder. The scary part? The email, the conference, the buyer all look totally normal. Here’s your move: if any email leads to a website that suddenly asks you to install a Chrome extension, like “Gemini AI assistant” or anything else, stop and report it to Security. Do not click Install.