China-Linked Hackers Share Chrome Exploit Lures

The Record · High sophistication
Last updated September 10, 2026

Proofpoint reported at least four espionage groups (mostly linked to Chinese state intelligence) using the same Chrome zero-day exploit kit (“BlueMoon”) to compromise victims and deliver malware. The operations used believable business and event-themed lures (internship inquiries, procurement requests, conference invites, and vaccination appointments), targeting U.S. defense contractors, NGOs, and government-related organizations in Southeast Asia.

How the attack worked

At least four separate cyber-espionage groups, mostly linked to Chinese state intelligence, were found using the same Chrome zero-day exploit kit, dubbed BlueMoon by Proofpoint. Rather than building separate exploit chains, the groups shared the same browser exploit and then deployed different malware depending on their objectives. This let multiple operations move quickly against a wide range of targets, including U.S. defense contractors, NGOs, and government-related organizations in Southeast Asia.

Each group used a business or event-themed lure tailored to its intended victims. These included fake internship inquiries, messages about an Asian Studies conference, procurement inquiries sent to aerospace and defense companies, and a fake vaccination appointment sent from a compromised Southeast Asian government email account. One operation went further after initial access, installing a browser extension disguised as Google's Gemini AI assistant that functioned as a browser-surveillance and credential-theft backdoor. Another used procurement-themed outreach to deliver ShadowPad, a backdoor associated with China-aligned activity.

Why it succeeded

The lures worked because they matched the professional context of the people receiving them. Procurement staff at defense and aerospace companies received what looked like ordinary requests for quotes. NGO program staff and researchers received internship and conference-related outreach that fit their normal correspondence. The vaccination appointment lure carried extra weight because it came from a compromised government email account, borrowing legitimacy from a real, trusted sender rather than a spoofed one.

The shared exploit kit also meant defenders faced a narrow window between a fix becoming available and attackers weaponizing it, a gap researchers described as no longer being rare.

What to watch for

  • Unsolicited procurement, internship, or conference-related messages that push quick action
  • Browser prompts asking to install or approve an extension you did not seek out
  • Extension branding that imitates a known product, such as an AI assistant, without coming from an official source
  • Appointment or administrative messages, even from apparently official senders, that request opening a link or file unexpectedly

How to build resistance

Organizations in procurement, HR, executive support, and NGO program roles should treat unsolicited business requests as higher risk and verify senders through a separate trusted channel before clicking links. Browser extensions should only come from approved corporate catalogs, with publishers confirmed as legitimate. Staff should also understand that even accounts belonging to known, trusted organizations can be compromised, so message content and context still matter. Finally, keeping browsers and endpoint protections updated as quickly as possible reduces the window attackers have to exploit newly disclosed flaws.

Key findings

  • At least four cyber-espionage groups used the same shared exploit kit (“BlueMoon”) against Chrome, then delivered different malware depending on the group.
  • Targets included “U.S. defense contractors, NGOs and Southeast Asian government agencies.”
  • Lures included “fake internship inquiries,” “messages about an Asian Studies conference,” “fake procurement inquiries,” “a fake vaccination appointment,” and “fake Indonesian conference invitations.”
  • One operation installed “a malicious browser extension disguised as Google’s Gemini AI assistant” that acted as “a browser-surveillance and credential-theft backdoor.”
  • Another operation used procurement-themed outreach to deliver ShadowPad (a backdoor associated with China-aligned activity).
  • One campaign used a “compromised Southeast Asian government email account,” increasing credibility.
  • Proofpoint noted the final delivery step was “surprisingly crude,” using curl to download malware into a temp folder, likely due to time pressure before patches landed.

Who’s being targeted

  • Commonly targeted roles: Procurement, Sales / Contracts / Proposals, HR / Recruiting, Executive assistants, NGO program staff, General staff (browser safety and extension installation).
  • Affected industries: Defense industrial base / aerospace and defense, Nonprofits / NGOs, Government (Southeast Asia), Consulting, Financial services, Manufacturing.
  • Attack channels: email.
  • Impersonated: Conference organizer or student/recruiter (external contact), Procurement office / buyer from a prospective customer, Southeast Asian government agency (from a compromised account).

Red flags to watch for

  • Unexpected outreach pushing you to click quickly (internship/professional event pitch you didn’t solicit)
  • Browser prompts to add an extension that you didn’t go looking for
  • Extension branding that imitates a well-known product (Gemini) but isn’t from an official source
  • Unsolicited procurement request from an unknown sender
  • Pressure to review a link/document immediately
  • Sender details that don’t match a known customer/vendor relationship
  • Appointment message you didn’t schedule or that doesn’t match local process
  • Unexpected link/attachment even though the sender appears to be government
  • Mismatch between the topic (vaccination) and your role/responsibilities
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the BlueMoon exploit kit?

BlueMoon is the name Proofpoint gave to a shared Chrome zero-day exploit kit used by at least four cyber-espionage groups to compromise browsers and deploy different malware.

Who was targeted in this campaign?

Targets included U.S. defense contractors, NGOs, and Southeast Asian government agencies, reached through lures like fake internship inquiries, procurement requests, and conference invitations.

How did the fake Gemini extension work?

One operation installed a malicious browser extension disguised as Google's Gemini AI assistant that functioned as a browser-surveillance and credential-theft backdoor.

Why did a compromised government email account matter?

A compromised Southeast Asian government email account was used to send a fake vaccination appointment lure, making the message appear more credible to the target.

Read the video transcript

You get an email: “Asian Studies conference, quick question.” Looks legit, even from a real .gov address. You click the link, and a Chrome window pops up asking to install a “Gemini AI assistant” extension. That’s BlueMoon at work, China-linked groups using a shared Chrome exploit kit to drop a fake Gemini that spies on your browser and steals credentials. Same trick hits defense and NGO staff with fake procurement RFQs too, open the link, Chrome gets exploited, and a backdoor like ShadowPad lands in a temp folder. The scary part? The email, the conference, the buyer all look totally normal. Here’s your move: if any email leads to a website that suddenly asks you to install a Chrome extension, like “Gemini AI assistant” or anything else, stop and report it to Security. Do not click Install.

Similar attacks

Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Recruitment Emails Hide BitB Google/Facebook Traps

Recruitment Emails Hide BitB Google/Facebook Traps

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes…

August 17, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026