Spy Groups Lured Victims to BlueMoon Exploit Links

The Hacker News · High sophistication
Last updated September 10, 2026

Proofpoint reports multiple espionage-focused threat groups used a shared exploit kit (“BlueMoon”) after tricking targets with spear-phishing emails to click malicious links. Visiting the attacker-controlled web pages triggered Chrome and Windows exploits to install malware (including a fake “Google Gemini” browser add-on) and establish persistence even after patching.

How the attack worked

Multiple espionage-focused threat groups relied on a shared exploit chain called BlueMoon to compromise targets. The starting point was familiar: a spear-phishing email designed to push the recipient toward an attacker-controlled link. Once a victim clicked, the landing page triggered browser and operating system flaws in succession, allowing a loader executable to run without further action from the target. In one variant, that loader installed a browser extension disguised as a legitimate Google Gemini add-on, which functioned as a browser-surveillance and credential-theft backdoor.

Why it succeeded

The technique worked because it exploited routine behavior rather than obvious deception. Clicking a link in a work email is an everyday action, and the lure content did not need to be elaborate to prompt that click. The addition of a fake extension named after a recognizable AI product added a layer of legitimacy for anyone who noticed an install prompt. Because several distinct groups used the same exploit chain independently, the pattern reflects a broadly effective delivery method rather than a one-off trick tied to a single actor.

What to watch for

  • Unexpected links in email, especially when the surrounding message does not match an ongoing business process
  • Any prompt to install or enable a browser extension that arrives from a link rather than an official browser store search
  • Extension names that mimic well-known products, which can create false trust
  • Pressure to click quickly rather than verify the request through a separate, trusted channel

How to build resistance

Organizations across the affected sectors, including NGOs, mining and commodity trading, aerospace, manufacturing, government, consulting, and financial services, should reinforce that unexpected links deserve scrutiny before any click. Staff should be encouraged to verify unusual requests through a known contact method rather than acting on the email alone. Because patching closes the initial browser vulnerability but does not remove anything already installed, teams should also treat suspected clicks as an incident requiring a persistence check, looking for unfamiliar browser extensions or unexpected scheduled tasks. Building this two-step habit, caution before the click and verification after a suspected one, reduces the practical impact of exploit chains like BlueMoon even when the initial lure succeeds.

Key findings

  • Multiple espionage groups used spear-phishing emails to push targets to attacker-controlled URLs that deployed the BlueMoon exploit chain.
  • Targets included U.S. NGOs, mining and commodity trading firms, U.S. aerospace companies, a Vietnamese manufacturing entity, and government/consulting/financial organizations in Indonesia and Singapore.
  • One observed outcome was a malicious browser extension “disguised as Google Gemini” used for “browser-surveillance and credential-theft.”
  • Patching closes the initial browser entry point, but may not remove persistence like installed extensions or scheduled tasks.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive leadership, NGO program and operations staff, Aerospace staff, Manufacturing staff, Finance teams, Government liaisons, IT/helpdesk and endpoint support.
  • Affected industries: Non-governmental organizations (NGOs), Mining, Physical commodity trading, Aerospace and defense, Manufacturing, Government, Consulting / professional services, Financial services.
  • Attack channels: email, website.
  • Impersonated: Unspecified (spear-phishing lure; sender identity not provided in article), Google Gemini (as a disguise for the malicious add-on).

Red flags to watch for

  • Unexpected link to an external site
  • Pressure to click rather than use official channels
  • Email context doesn’t match a known ongoing business process
  • Extension installation prompted from a link in an email
  • Extension name mimics a well-known brand/product
  • Any request to add/install software to view a document or proceed
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the BlueMoon exploit kit?

BlueMoon is a shared exploit chain used by multiple espionage-focused threat groups that is triggered when a target clicks a spear-phishing link to an attacker-controlled landing page, exploiting Chrome and Windows flaws to install malware.

How did the fake Google Gemini extension work?

After a victim clicked a malicious link, a loader executable installed a browser add-on disguised as Google Gemini, which acted as a browser-surveillance and credential-theft backdoor called GemStone.

Does patching remove this threat once a user has clicked the link?

No. Patching closes the initial browser exploit entry point, but it does not remove persistence mechanisms already installed, such as the malicious extension or scheduled tasks.

Which industries were targeted in this campaign?

Targets included U.S. NGOs, mining and commodity trading firms, aerospace companies, a Vietnamese manufacturing entity, and government, consulting, and financial organizations in Indonesia and Singapore.

Read the video transcript

You get an email: “Please review the information at this link.” Looks normal… but that one click can quietly hijack your browser. That link can lead to a BlueMoon exploit page. In seconds, it abuses Chrome and Windows, then drops a fake “Google Gemini” browser extension that spies on your browsing and steals credentials. Here’s the nasty part: even if you patch Chrome later, BlueMoon’s payload can stay, like that GemStone-style extension or scheduled tasks, quietly watching everything you do. If an email link ever leads to a page asking you to install a browser add-on, especially something like “Google Gemini” to view a file, stop and report it to Security immediately.

Similar attacks

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
APT31 Phish Drops Fake “Gemini” Extension

APT31 Phish Drops Fake “Gemini” Extension

Multiple China-aligned espionage groups used phishing emails to deliver a “BlueMoon” exploit chain that abused three zero-day flaws in Chrome/Chromium and Windows. In observed campaigns, victims who clicked the phishing link ended up with a malicious browser extension disguised as Google Gemini,…

September 9, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026