Chinese state espionage groups weaponize shared 'BlueMoon' Chrome zero-day against US defense and Asian targets

Four Chinese state hacking teams hit the same target at the same time with the same stolen key. According to disclosures reported by The Record, state espionage clusters simultaneously deployed a zero-day exploit kit dubbed BlueMoon against American defense contractors and Southeast Asian government ministries. The exploit weaponized an unpatched Chromium memory-corruption flaw and a Windows kernel vulnerability, slipping through enterprise firewalls during a critical four-week patch window.

The blitz is the direct result of Beijing’s 2021 vulnerability disclosure law, which mandated state exploit stockpiling and centralized vulnerability weaponization. Chinese researchers are legally barred from disclosing software bugs to developers until they hand them over to the Ministry of State Security. Instead of helping vendors fix security holes, intelligence agencies stockpile them, distributing turnkey attack kits across multiple hacking units to maximize offensive hits before vendors can patch.

The strategy relies on aggressive patch-gap exploitation. By targeting everyday browser software used by millions, Beijing converts consumer code into offensive weapons. Defense suppliers and regional ministries are left vulnerable while Chinese intelligence agencies hoard zero-days for state espionage.

Read primary reporting on The Record →