The BlueMoon exploit kit was built with AI assistance
Assessment
Proofpoint observed development artifacts left in the distributed BlueMoon samples — extensive logging, verbose comments, evidence of iterative debugging, and references to markdown handover documentation and the v8CTF bug-bounty framework — that are consistent with AI-assisted development. But Proofpoint is explicit that 'no single artifact conclusively confirms' AI involvement. The observation is a reasonable, hedged inference from suggestive tooling artifacts, not a demonstrated fact. Given the intense interest in AI-written malware, a reader could easily convert Proofpoint's careful 'suggestive but not conclusive' into 'BlueMoon was built by AI,' which overstates what the evidence supports.
Where this claim appeared
Proofpoint · 2026-09-30
https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploitWhat “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
BlueMoon: four state-aligned actors chain two patch-gap Chrome zero-days and a Windows LPE within 12 daysThink this assessment is wrong? Report an error.