Spear-Phish Links Victims to Real University Site

About DFIR · High sophistication
Last updated September 17, 2026

Researchers reported real-world attacks against NGOs that started with a spear‑phishing email containing a link to a legitimate (but vulnerable) university website. Clicking the link redirected victims into a multi-step exploit chain that ultimately gave attackers full control of the victim’s computer and enabled follow-on spying and credential theft.

Key findings

  • At least two China-linked threat clusters targeted NGOs using the same Chrome+Windows zero-day exploit chain (“BlueMoon”).
  • The initial entry point was a spear-phishing email that linked to a legitimate university website vulnerable to reflected XSS.
  • After compromise, one cluster used a JScript backdoor for reconnaissance/command execution; another installed a credential-stealing Chrome extension.

Who’s being targeted

  • Commonly targeted roles: All employees (NGOs), Executives and executive assistants, Research/program teams, IT/helpdesk.
  • Affected industries: Nonprofits / NGOs.
  • Attack channels: email, website.
  • Impersonated: A legitimate university website (used as a lure/redirector).

Awareness takeaways

  • Treat unexpected links as risky even if they point to a legitimate website, attackers can abuse real sites as stepping stones.
  • If you click a link and the page quickly redirects or behaves oddly, stop and report it, this can be a sign of an attack chain in progress.
  • Prioritize rapid browser/OS patching because attackers actively exploit the time gap between upstream fixes and user-installed updates.

Red flags to watch for

  • Unexpected email pushing you to click a link, even though it points to a legitimate-looking site
  • Link leads to a real website but quickly redirects you elsewhere
  • The message lacks context (why you, why now) and doesn’t follow normal collaboration channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “University brief, please review.” Looks legit, link goes to a real .edu site. Safe, right? In real attacks, clicking that link hit a vulnerable university page with reflected XSS, then silently redirected into a “BlueMoon” Chrome and Windows zero‑day chain that took over the computer. Aha moment: the link itself looked fine. The giveaway was what happened after. The real university page flashed, then quickly bounced to another site and the browser behaved oddly. If you click a link and a real site instantly redirects or acts weird, stop using that browser, take a screenshot, and report it to Security right away.

Similar attacks

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
NGOs Lured via Donation Form Into Chrome 0-Day Chain

NGOs Lured via Donation Form Into Chrome 0-Day Chain

Researchers reported two China-linked groups targeting NGOs with spear-phishing that led victims through a legitimate U.S. university website before redirecting them to attacker infrastructure. The attackers used a chained Chrome/Windows exploit to take control, then deployed different payloads,…

September 15, 2026
Spear-Phishing Link Triggers Chrome-Windows Exploit

Spear-Phishing Link Triggers Chrome-Windows Exploit

China-linked attackers targeted NGOs with spear-phishing emails that urged recipients to click a link to a legitimate U.S. university website. The link path abused a website flaw to silently redirect victims to attacker infrastructure, which then exploited Chrome and Windows to install malware…

September 15, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026