Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

A coordinated assault on web applications has left multiple organizations scrambling to patch vulnerabilities after four separate spy groups were found to be utilizing a shared Chrome and Windows exploit kit within a week. This alarming trend highlights the ease with which attackers can leverage existing tools to breach sensitive systems, underscoring the importance of proactive security measures.

The exploit kit in question, attributed to an anonymous group known only as “DarkTear,” has been used by multiple nation-state actors to gain unauthorized access to web applications and user data. The tool exploits a pair of vulnerabilities: CVE-2022-3393, affecting Chrome’s V8 JavaScript engine, and CVE-2021-40444, impacting Windows’ MSHTML rendering engine. These weaknesses allow attackers to execute arbitrary code on compromised systems, effectively granting them the ability to pivot through networks and exfiltrate sensitive information.

One of the affected organizations is a prominent multinational corporation, which revealed that its web application was breached using DarkTear within days of the initial exploit kit deployment. The company’s cybersecurity team quickly identified the vulnerability and applied patches to mitigate further attacks, but not before sensitive data had been compromised. Another victim, a government agency, took longer to respond, resulting in a prolonged period of unauthorized access.

DarkTear’s exploit kit is notable for its sophistication and flexibility. By targeting these specific vulnerabilities, attackers can bypass traditional security controls and gain a foothold within a network. Once inside, they can move laterally, using techniques such as cross-domain privilege escalation to evade detection and maintain persistence. This allows them to unlock active attack paths, creating opportunities for further exploitation.

The fact that four separate spy groups have used the same exploit kit within a week underscores the efficiency of DarkTear’s development process. It also highlights the challenges facing security professionals in keeping pace with evolving threat landscapes. As attackers continue to adapt and improve their tools, it is essential for organizations to adopt proactive security strategies, including regular vulnerability assessments, patch management, and employee education.

To protect against similar attacks, we recommend that organizations prioritize web application security and keep their systems up-to-date with the latest patches. Employees should also be trained to recognize and report suspicious activity, as early detection can significantly mitigate the impact of a breach. By staying vigilant and proactive in the face of evolving threats, businesses can reduce their exposure to exploitation and minimize the risk of sensitive data being compromised.


Source: The Hacker News — 2026-09-09