One Exploit Chain, Four Unrelated Spy Groups

Proofpoint disclosed on September 9 that four separate espionage-motivated hacking groups, most with a suspected China nexus, had independently adopted the same exploit chain within a 12-day span, a novel tool the researchers named BlueMoon. TA412, a Chinese state-sponsored actor also tracked as JungleBamboo, Violet Typhoon and APT31, was first observed using it on August 28 against US NGOs, mining firms and commodity trading companies. UNK_LateNight followed on September 2 against US aerospace and defense targets, UNK_DoubleCheck the same day against a Vietnamese manufacturer, and UNK_QuietRacket on September 3 against government, consulting and financial targets in Indonesia and Singapore.

The chain combines two Chrome vulnerabilities in the browser's V8 engine, a type-confusion flaw and a sandbox escape, with a Windows kernel privilege-escalation bug that affects older builds. None of the four groups appear to be working together in any conventional sense; their targets, regions and prior toolkits do not overlap. What they share is a four-week-old capability that all four picked up almost simultaneously.

The Window That Made This Possible

The underlying Chrome fix was committed to the open-source Chromium codebase on August 7. The patched version did not reach Chrome's stable release channel, the version that actually updates on most users' machines, until September 3.

DateEvent
August 7Chrome fix committed to open-source code, visible to anyone watching
August 28TA412 first observed exploiting the flaw, before the stable patch existed
September 2 to 3Three more unrelated groups adopt the same exploit chain
September 3Patched Chrome finally reaches the stable release channel

That nearly four-week gap between a fix landing in public code and a patched build reaching ordinary users is a known risk in open-source browsers, and TA412's August 28 activity shows it was exploited as a genuine zero-day before Chrome's own defense was even available to install. The three groups that followed in early September may have built their own version from the same public disclosure rather than copying TA412 directly, which would explain near-simultaneous adoption without any coordination between them.

Proofpoint's Own Explanation Is the Real Story

Four unrelated state-aligned groups converging on one exploit chain within 12 days is not how this capability usually spreads. Proofpoint's own assessment calls it "a rushed deployment rather than a mature, long-planned operation," and points to a specific likely cause: AI agents lowering the cost and skill barrier for building working exploits from a public vulnerability disclosure. The researchers name two possible explanations that are not mutually exclusive, a shared commercial exploit-broker supplying multiple state clients at once, or AI-assisted development letting each group build its own version fast enough to look coordinated even without contact between them.

Either explanation describes the same shift: the gap between a vulnerability becoming public and a working exploit reaching multiple hands used to be measured in months. Here it was measured in days, across four groups with no known relationship. The exploit chain is the incident. The compressed timeline is the trend, and it will outlast this specific patch cycle.

This Is Not Only an Aerospace and Mining Problem

The named targets so far sit in aerospace, defense, mining, commodity trading and government consulting outside Europe, but the vulnerable software is Chrome and Windows, installed on essentially every desktop an EU or UK business runs. A capability that spread to four unrelated state-aligned groups in under two weeks does not stay confined to its first targets, and the falling cost Proofpoint describes applies to whichever industry or region a fifth or sixth group decides to point it at next.

The concrete action item survives the specific CVE numbers: any organization not fully current on Chrome's stable channel and the latest Windows security updates was exposed for most of a month, and NIS2's incident-reporting obligations already require knowing whether that patch actually reached every managed device, not just that an update was published. If AI-assisted exploit development keeps compressing this timeline the way Proofpoint suggests, the practical gap between a fix existing and a fix protecting you is the number that matters, not the CVE severity score.