MalwareTips News BlueMoon attacks target outdated Chrome and Windows PCs

How quickly do you normally install browser and Windows updates?

  • As soon as prompted

    Votes: 6 75.0%
  • Within a few days

    Votes: 2 25.0%
  • Only after repeated reminders

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    8

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
8
23
1
A shared exploit kit called BlueMoon has been used by four espionage groups to attack Chrome users on Windows. People who delay browser or operating system updates may remain exposed to flaws already used in real-world attacks.

Phishing links start the attack​

Malwarebytes Labs reports that the attacks begin with phishing emails. Clicking a malicious link can open a page that targets two flaws in Chrome’s V8 JavaScript engine and then a Windows flaw to escape browser protections and gain greater control of the PC.

This chain does not make every phishing link successful, nor does it remove all protection from a PC. It specifically targets systems that have not received the relevant Chrome and Windows fixes.


Attackers moved quickly​

The Chrome fixes reached the Stable channel on September 3 and September 8, 2026. One Chrome flaw was already under active attack when Google issued its update, while Microsoft’s September Patch Tuesday addressed the Windows flaw after exploitation had also begun.

CISA later added all three vulnerabilities to its Known Exploited Vulnerabilities catalog, a list of security flaws confirmed as exploited in real attacks.

Researchers also found clues that AI may have assisted the kit’s development, but they did not find conclusive evidence. The firmer finding is that several groups adopted the same exploit chain within days of one another.

What home users should do​

Give Chrome and Windows updates priority when flaws are already being exploited. Restarting when prompted helps complete updates that may otherwise remain pending.

  • Install browser and Windows security updates promptly instead of repeatedly postponing them.
  • Do not open links in unsolicited emails, even if the message tries to create urgency.
  • Keep real-time anti-malware protection enabled and updated to help detect malware that exploit kits try to install.