Spy Groups Phish Victims Into Chrome Exploit Kit

eSecurity Planet · High sophistication
Last updated September 11, 2026

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were chained to install malware and gain higher system permissions. Even after patching, affected machines may still contain backdoors or other persistence.

How the attack worked

Four separate espionage groups were observed using the same BlueMoon exploit kit within about a week of each other, targeting organizations in the US and Southeast Asia. The attack chain began with ordinary phishing emails that directed targets to attacker-controlled websites. Once a victim clicked through in Chrome or a Chromium-based browser, BlueMoon chained browser exploits with a Windows vulnerability to escape the sandbox, elevate privileges, and deliver operator-selected malware.

One of the campaigns, attributed in the reporting to TA412 (also tracked as APT31), targeted NGOs, mining companies, and commodity trading firms with a lure that resulted in the installation of GemStone, a malicious Chrome extension disguised as Google's Gemini AI assistant. Other campaigns deployed different payloads, including ShadowPad and other malware families.

Why it succeeded

The lure itself was simple: an email prompting the recipient to click a link and view content on a website. There was no need for the message to be elaborate, because the real work happened after the click, inside the browser exploit chain. This makes the initial phishing message harder to flag through content alone, since red flags rely more on context (an unexpected email pushing urgent link-clicking) than on obvious grammar or spoofing errors.

The speed of adoption across four separate groups is also notable. Once one group demonstrated a working exploit chain, others adopted nearly identical code within days, leaving little time between disclosure of a fix and active exploitation in the wild.

What to watch for

  • Unexpected emails prompting an urgent visit to a website, especially with a link to an unfamiliar or unrelated domain
  • Requests to install a browser extension outside of normal IT-approved channels, including extensions claiming to be well-known tools like an AI assistant
  • Unusual browser or system behavior right after clicking an email link
  • Suspicious process activity or scheduled tasks on endpoints, which security teams can use as investigation clues

Building resistance

Organizations affected or at risk, including NGOs, mining and commodities firms, aerospace, manufacturing, government, consulting, and financial services, should reinforce a few habits. Staff across all roles, not just executives, should treat unsolicited emails with links as high risk, particularly when there is pressure to act immediately. IT and helpdesk teams should reiterate that browser extensions are only installed through approved, official channels. Because patching alone does not remove malware or persistence mechanisms already installed before an update, endpoint checks should follow emergency patches rather than being treated as optional. Fast, clear reporting channels for suspicious browser behavior give defenders a better chance of catching activity during the narrow window between vulnerability disclosure and active exploitation.

Key findings

  • Four espionage groups adopted the same BlueMoon exploit kit within about a week, reducing defenders’ response time.
  • The attack chain started with phishing emails that sent targets to attacker-controlled websites, then used Chrome and Windows exploits to escape the sandbox and elevate privileges.
  • One campaign installed “GemStone,” a malicious Chrome extension disguised as Google’s Gemini AI assistant; other campaigns deployed ShadowPad and other malware.
  • Even if systems are patched, organizations may still need endpoint checks because malware/persistence could already be present.
  • Proofpoint shared investigation clues such as unusual process chains (chrome.exe spawning cmd.exe then curl.exe) and suspicious scheduled tasks.

Who’s being targeted

  • Commonly targeted roles: All employees (phishing awareness), Executives and assistants, NGO program teams, Aerospace staff, Mining/commodities staff, IT/helpdesk and endpoint teams.
  • Affected industries: Nonprofits/NGOs, Mining and commodities, Aerospace, Manufacturing, Government, Consulting/Professional services, Financial services.
  • Attack channels: email, website.
  • Impersonated: Unspecified (email sender not identified in article), Google Gemini AI assistant (impersonated via extension disguise).

Red flags to watch for

  • Unexpected email prompting you to visit a website
  • Link leads to an unfamiliar or unrelated domain
  • Request to view urgent content without prior context
  • Browser/extension install prompted from outside official stores or standard IT processes
  • An extension claims to be a well-known brand but appears after visiting a random website
  • Unexpected Chrome behavior after clicking an email link
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the BlueMoon exploit kit?

BlueMoon is an exploit kit that chains Chrome and Windows vulnerabilities to escape the browser sandbox and elevate privileges after a victim clicks a phishing link to an attacker-controlled website.

How did victims first get compromised?

The attacks started with phishing emails that directed targets to attacker-controlled websites, which then triggered the browser-based exploit chain.

What was GemStone?

GemStone was a malicious Chrome extension disguised as Google's Gemini AI assistant, installed as part of one of the campaigns targeting NGOs, mining companies, and commodity trading firms.

Is patching enough to remove the threat?

No. Patching closes the vulnerabilities, but it does not remove malware or persistence mechanisms that were already installed on a system before the update, so endpoint checks are still needed.

Read the video transcript

You get an email: “Please review the information at the link below.” Looks boring, right? That click is all BlueMoon needs. Behind that link is the BlueMoon exploit kit. It hits Chrome, then Windows, and can quietly drop tools like a fake Gemini AI Chrome extension called GemStone. Here’s the scary part: even after we patch Chrome and Windows, BlueMoon’s backdoors and scheduled tasks can still be sitting on that machine, waiting. If you ever click a link and Chrome suddenly asks to install an assistant or extension, stop and hit Report Phishing so IT can check your machine fast.

Similar attacks

BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Spy Groups Lured Victims to BlueMoon Exploit Links

Spy Groups Lured Victims to BlueMoon Exploit Links

Proofpoint reports multiple espionage-focused threat groups used a shared exploit kit (“BlueMoon”) after tricking targets with spear-phishing emails to click malicious links. Visiting the attacker-controlled web pages triggered Chrome and Windows exploits to install malware (including a fake…

September 9, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Fake Resumes + Watering Holes Hit AnySign4PC Users

Fake Resumes + Watering Holes Hit AnySign4PC Users

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download…

July 30, 2026