Chaotic Eclipse, also referred to as Nightmare Eclipse, is an anonymous security researcher or exploit developer persona associated with a series of public Microsoft Windows zero-day and proof-of-concept disclosures beginning in 2026. The activity is notable for publishing practical local and physically assisted attack techniques against native Windows security mechanisms rather than for documented intrusion operations, victimization campaigns, or financially motivated extortion. Publicly attributed disclosures linked to this persona include YellowKey, GreenPlasma, MiniPlasma, and UnDefend. YellowKey was assigned CVE-2026-45585 and is a BitLocker security feature bypass affecting TPM-only deployments on supported Windows platforms. The technique abuses Windows Recovery Environment behavior to obtain a SYSTEM-level shell after the protected volume has been unlocked by the TPM, enabling post-boot access without the user’s password or recovery key when brief physical access is available. GreenPlasma was presented as a privilege-escalation technique leveraging Windows object manager behavior and trusted path redirection. MiniPlasma was described as a local privilege-escalation method targeting the Windows Cloud Files filter driver through a race condition related to the code path previously associated with CVE-2020-17103. UnDefend was described publicly as a Microsoft Defender zero-day technique capable of preventing signature updates from a standard user context without administrator privileges, although some details were reportedly withheld and no CVE assignment was noted. Across these disclosures, Chaotic Eclipse demonstrates strong capability in Windows internals, local privilege escalation, security feature bypass, and defense impairment. The techniques emphasize abuse of legitimate operating system functionality, recovery-environment manipulation, object manager behavior, race conditions, and low-artifact execution paths. Available information supports characterization as a public exploit-disclosure persona focused on exposing Windows security weaknesses; it does not support high-confidence attribution to a nation state, ransomware operation, or established intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
For background on the earlier tools in this series, see our analysis of BlueHammer (CVE-2026-33825) and RedSun (CVE-2026-41091).
RedSun CVE-2026-41091 Microsoft Defender Local privilege escalation through link-following behavior Fixed in engine versions at or above 1.1.26040.8; listed in CISA KEV.
UnDefend CVE-2026-45498 Microsoft Defender Antimalware Platform Denial of service / Defender disruption Fixed in platform versions at or above 4.18.26040.7; listed in CISA KEV.
RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM. Microsoft eventually acknowledged the bug... and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly disclosing and releasing proof-of-concept exploit techniques targeting Microsoft Windows, including YellowKey for BitLocker/WinRE bypass, GreenPlasma for privilege escalation through Windows internals, and MiniPlasma for local privilege escalation via the Cloud Files filter driver.
Presented as the actor or researcher behind 'UnDefend,' described here as releasing a third Microsoft Defender zero-day that blocks signature updates without requiring administrator privileges.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.