ThreatPaper
Weak Evidence

The BlueMoon exploit kit was built with AI assistance

Assessment

Proofpoint observed development artifacts left in the distributed BlueMoon samples — extensive logging, verbose comments, evidence of iterative debugging, and references to markdown handover documentation and the v8CTF bug-bounty framework — that are consistent with AI-assisted development. But Proofpoint is explicit that 'no single artifact conclusively confirms' AI involvement. The observation is a reasonable, hedged inference from suggestive tooling artifacts, not a demonstrated fact. Given the intense interest in AI-written malware, a reader could easily convert Proofpoint's careful 'suggestive but not conclusive' into 'BlueMoon was built by AI,' which overstates what the evidence supports.

Where this claim appeared

Proofpoint · 2026-09-30

https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

BlueMoon: four state-aligned actors chain two patch-gap Chrome zero-days and a Windows LPE within 12 days

Think this assessment is wrong? Report an error.