ThreatPaper
Assessed, Not Confirmed

Four Chinese state-sponsored groups used the BlueMoon exploit kit

Assessment

Coverage frames BlueMoon as four Chinese nation-state actors sharing one exploit kit. The lead cluster, TA412, is a well-established China-aligned actor (also tracked as APT31 and Violet Typhoon), so its attribution is solid. But the other three are espionage-motivated clusters Proofpoint tracks under provisional UNK_ designations (UNK_LateNight, UNK_QuietRacket, UNK_DoubleCheck), and Proofpoint states UNK_DoubleCheck's attribution is unclear. So 'four Chinese state groups' overstates the confidence for at least one cluster. Equally important, the near-simultaneous adoption of the same non-trivial chain within about twelve days points to a shared supplier or quartermaster distributing the kit, rather than four groups independently discovering and weaponising the same three vulnerabilities. The multi-actor use is real; the 'four confirmed Chinese APTs' framing is more certain than the evidence.

Where this claim appeared

Security Affairs · 2026-09-30

https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-days.html

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

BlueMoon: four state-aligned actors chain two patch-gap Chrome zero-days and a Windows LPE within 12 days

Think this assessment is wrong? Report an error.