메뉴
BL
Ars Technica • 16일 전

동일한 크롬·윈도우 익스플로잇 킷 사용하는 해킹 그룹 4곳 적발

IMP
8/10
핵심 요약

보안업체 Proofpoint는 크로미움 기반 브라우저와 구형 윈도우의 치명적 취약점 3개를 연쇄 공격하는 'BlueMoon' 익스플로잇 킷이 최소 4개 해킹 그룹에 의해 활발히 사용되고 있다고 밝혔다. 이 중 2개 그룹은 중국 정부와 연계된 국가 후원 사이버 간첩 조직으로, 미국 내 NGO·광산·우주항공 기업 등을 표적으로 삼았다. AI가 취약점 발견과 익스플로잇 개발 비용을 낮추면서 '패치 갭'을 노린 고급 공격 능력의 진입장벽이 크게 낮아졌다는 점이 이번 사건의 핵심 시사점이다.

번역된 본문

크로미움(Chromium) 기반 브라우저와 구형 버전 윈도우의 치명적인 취약점을 표적으로 하는 거의 동일한 익스플로잇 킷이 최소 4개 해킹 그룹에 의해 활발히 사용되고 있으며, 이 중 일부는 중국 정부와 연계된 것으로 확인됐다.

보안업체 Proofpoint의 연구진은 수요일(현지시간) 자신들이 'BlueMoon'이라고 명명한 이 킷이 3개 취약점을 연쇄적으로(chain) 이용해 공격자가 원하는 악성코드를 설치할 수 있게 해준다고 밝혔다. BlueMoon은 크로미움 취약점 2개와 윈도우 10(2018년 10월 업데이트), 윈도우 서버 2019, 윈도우 10 2004, 윈도우 서버 2022, 윈도우 11 초기 버전의 커널 취약점 1개를 악용한다. 세 취약점 모두 최근 24시간 내에 패치가 배포됐다.

신속하게 배포되고 광범위하게 공유

이번 공격은 많은 캠페인에서 볼 수 있는 은밀함이 부족했다. 해커들은 보통 새로 발견된 취약점을 아껴가며 사용해 수명을 늘리려 한다. Proofpoint는 이처럼 광범위하게 사용되고 탐지 신호가 강한 익스플로잇 체인이 나온 이유 중 하나로 크로미움 공급망의 '패치 갭(patch gap)'을 이용하려는 의도로 추정했다. 패치 갭이란 개발사가 패치를 제공한 시점과 해당 패치가 크롬·엣지 등 브라우저에 반영되는 시점 사이의 기간을 말한다. 또 다른 요인으로는 인간만의 발견보다 빠르게 취약점을 찾아내는 AI의 사용 가능성이 꼽혔다. 이 두 가지 요인이 기회의 창이 닫히기 전에 신속히 움직이도록 공격자를 재촉했을 것으로 보인다.

Proofpoint는 다음과 같이 설명했다. "완전히 무기화된 크롬 익스플로잇 체인은 역사적으로 매우 가치 있고 희귀한 능력이었다. BlueMoon은 개발된 후 빠르게 배포되었고, 높은 탐지 신호를 내면서도 며칠 만에 여러 위협 행위자들에게 공유되었다. 이는 AI 에이전트가 위협 행위자의 익스플로잇 개발을 점점 더 지원하면서 이러한 급의 능력에 대한 비용과 진입장벽이 낮아졌음을 반영할 수 있다. 이는 크로미움 같은 오픈소스 코드베이스에서 특히 중요한데, 상류(upstream) 패치가 하류(downstream) 사용자들이 패치를 적용하기 전에 공개적으로 접근 가능하기 때문이다. 이로 인해 위협 행위자들이 하류 안정 버전 출시 전에 패치를 신속히 역설계하고 익스플로잇을 개발하려는 기회의 창이 생긴다."

4개 그룹은 광범위한 조직과 기업을 표적으로 삼았다. 그룹과 표적은 다음과 같다.

  • TA412: 2024년 미국 정부가 중국 민간 대외정보기관을 대신하여 기소한 중국 성향의 국가 후원 위협 행위자로, 미국의 비정부기구(NGO), 광산 기업, 실물 상품 거래 회사들을 반복적으로 공격
  • UNK_LateNight: 두 번째 중국 성향 간첩 그룹으로, 미국 우주항공 기업 다수를 표적으로 삼음
  • UNK_DoubleCheck: 세 번째 그룹으로, 베트남 제조업체를 표적으로 삼음
  • UNK_QuietRacket: 싱가포르와 인도네시아에서 활동

첫 공격은 TA412가 8월 28일 시작했으며, 나머지는 이달 초부터 시작됐다. Proofpoint는 다른 그룹도 이 익스플로잇 킷에 접근했는지는 알 수 없다고 밝혔다.

크롬을 겨냥한 두 취약점은 모두 구글의 오픈소스 자바스크립트 엔진인 V8에 존재했다. 공격자는 V8 타입 컨퓨전(type confusion) 버그와 별도의 V8 샌드박스 탈출 취약점을 악용해 원격 코드 실행을 달성했다. 이후 구형 윈도우의 로컬 권한 상승 취약점을 이용해 악성 코드가 시스템 권한으로 실행되도록 했다.

첫 번째 V8 취약점은 CVE-2026-85046으로, 윈도우 버그는 CVE-2026-85880으로 추적된다. 구글은 V8 샌드박스 탈출에는 CVE 번호를 부여하지 않는다.

Proofpoint는 "관찰된 활동 당시 두 V8 취약점 모두 '패치 갭' 제로데이였다. 즉, 공개된 상위 크로미움 소스 코드에서는 이미 수정된 알려진 취약점이었지만, 일반에 배포된 크롬 및 크로미움 기반 브라우저의 최신 안정 버전에서는 패치되지 않은 상태로 남아 있었다. 익스플로잇 킷 개발자가..."라고 설명했다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government. Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours. Deployed rapidly, widely shared The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans. Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint said: A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases. The four groups targeted a wide range of organizations and companies. The groups and targets included: TA412, a China-aligned state-sponsored threat actor indicted by the US government in 2024 on behalf of China’s civilian foreign intelligence agency, repeatedly hit organizations focused on non-governmental organizations, mining companies, and physical commodity trading firms in the US UNK_LateNight, a second China-aligned espionage group, targeted multiple US aerospace companies A third group, UNK_DoubleCheck, targeted a Vietnamese manufacturing entity UNK_QuietRacket activity targeted Singapore and Indonesia The first attack came from TA412 and began on August 28. The remainder began earlier this month. Proofpoint said it’s unknown if other groups also gained access to the exploit kit. Both vulnerabilities targeting Chrome resided in V8, Google’s open source JavaScript engine. Exploiting a V8 type confusion bug and a separate sandbox escape in V8, the attackers were able to execute remote code. They then used a local privilege escalation in older versions of Windows to allow the malicious code to run with system rights. The first V8 vulnerability is tracked as CVE-2026-85046, and the Windows bug is tracked as CVE-2026-85880. Google doesn’t assign CVE designations for V8 sandbox escapes. “Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.” While BlueMoon leaves plenty of indications that it’s being used and all three vulnerabilities have been patched, Proofpoint said the kit may nonetheless continue to be used. “Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers,” the researchers said. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 5 Comments