Chinese state espionage groups weaponize shared 'BlueMoon' Chrome zero-day against US defense and Asian targets

Sources (2) Direct reporting & OSINT telemetry
Key Intelligence Takeaways
  • Multiple distinct Chinese state espionage groups simultaneously weaponized a Chrome V8 zero-day ('BlueMoon') against Western defense entities.
  • Synchronized exploitation points to centralized vulnerability brokering managed by Chinese state intelligence.
  • Exploit delivered through watering-hole attacks on targeted engineering and aerospace industry forums.

Four Chinese state hacking teams hit the same target at the same time with the same stolen key. According to disclosures reported by The Record, state espionage clusters simultaneously deployed a zero-day exploit kit dubbed BlueMoon against American defense contractors and Southeast Asian government ministries. The exploit weaponized an unpatched Chromium memory-corruption flaw and a Windows kernel vulnerability, slipping through enterprise firewalls during a critical four-week patch window.

The blitz is the direct result of Beijing’s 2021 vulnerability disclosure law, which mandated state exploit stockpiling and centralized vulnerability weaponization. Chinese researchers are legally barred from disclosing software bugs to developers until they hand them over to the Ministry of State Security. Instead of helping vendors fix security holes, intelligence agencies stockpile them, distributing turnkey attack kits across multiple hacking units to maximize offensive hits before vendors can patch.

The strategy relies on aggressive patch-gap exploitation. By targeting everyday browser software used by millions, Beijing converts consumer code into offensive weapons. Defense suppliers and regional ministries are left vulnerable while Chinese intelligence agencies hoard zero-days for state espionage.

What People in China Are Saying

Tech channels on Bilibili and Zhihu celebrated Chinese security researchers' zero-day discovery prowess, while downplaying foreign intelligence exploitation.

Censorship & Information Control in China

Domestic cyber discussions are strictly required to attribute exploits to academic research, banning any mention that exploits were brokered via the Ministry of State Security's vulnerability disclosure mandate.

Context & Operational Notes

China's 2021 vulnerability reporting regulations require all zero-days discovered by Chinese citizens to be handed to government authorities before software vendors.