Four hacking groups, some with Chinese government ties, are actively using BlueMoon, an exploit kit that chains vulnerabilities in Chromium browsers and Windows to install malware. Researchers from Proofpoint identified the kit being rapidly deployed and shared across multiple threat actors within days, exploiting a patch gap in the Chromium supply chain and potentially leveraging AI for faster vulnerability discovery.