Nightmare Eclipse is an anonymous exploit developer and vulnerability-disclosure actor active since April 2026, also known as Nightmare-Eclipse, NightmareEclipse, Chaotic Eclipse, Infinite Nightmare, MSNightmare, and Dead Eclipse. The activity is attributed to a single researcher publishing Windows exploitation tools and zero-day proof-of-concept code without coordinated vendor disclosure. The actor's public identity, geographic origin, and organizational affiliation are unknown. The releases primarily target Microsoft Defender and adjacent Windows security components, with later tools addressing CrowdStrike Falcon, Avast Antivirus, Kaspersky Endpoint Security, and NVIDIA GPU drivers. Their techniques frequently abuse trusted functionality and privileged file operations rather than memory corruption, combining race conditions, opportunistic locks, Cloud Files behavior, NTFS junctions, Object Manager symbolic links, registry-hive manipulation, and scheduled-task or COM execution. Demonstrated capabilities include escalation from a standard user to SYSTEM, local password-hash extraction, DLL sideloading, and interference with endpoint protection. Notable releases include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend, RoguePlanet (CVE-2026-50656), and ShieldBreak (CVE-2026-69414). BlueHammer exposes sensitive registry data and supports local administrator compromise; RedSun and ShieldBreak redirect Defender remediation into privileged payload placement and execution. UnDefend blocks Defender signature updates and can disable protection. GreatXML provides a post-compromise persistence and BitLocker-protected data-access technique requiring prior administrator access and subsequent physical access. LegacyHive demonstrates cross-user registry-hive loading but is not a complete privilege-escalation chain. Independently reproduced third-party releases include FalconFlank, PrettyPrague, and HardBreacher. GreenSection has demonstrated crash behavior rather than privilege escalation, while the published ShieldCrash implementation failed independent testing of its claimed privileged file-read capability. BlueHammer, RedSun, and UnDefend have been exploited in real-world intrusions, including ransomware operators' use of BlueHammer. Such downstream exploitation does not establish that Nightmare Eclipse conducted those intrusions or operated ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
BlueHammer, CVE-2026-33825, was an April 2026 Defender privilege-escalation vulnerability described as a time-of-check to time-of-use race combined with path confusion. CISA added it to the KEV catalog, and ransomware operators were confirmed exploiting it.
The content states that BlueHammer, RedSun, and UnDefend have all been confirmed exploited in the wild.
The content states that BlueHammer, RedSun, and UnDefend have all been confirmed exploited in the wild.
RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM. Microsoft eventually acknowledged the bug... and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A public, uncoordinated vulnerability-research cluster that publishes proof-of-concept tools abusing trusted operating-system and endpoint-security functionality. Its releases concentrate on local privilege-escalation and file-read paths in security products, especially Microsoft Defender. The current ShieldCrash release claims a SYSTEM-level arbitrary-file-read bypass of the ShieldBreak patch, but the published code did not reproduce the claimed read primitive because its redirect chain fails at a timing-sensitive reparse-point stage.
A researcher-linked zero-day disclosure cluster that publicly released four uncoordinated proof-of-concept exploits between August 29 and September 3, 2026, affecting CrowdStrike Falcon Sensor, NVIDIA GPU drivers, Avast Antivirus, and Kaspersky Endpoint Security. The cluster reportedly has fourteen public zero-day releases over five months.
A prolific independent zero-day researcher persona publishing uncoordinated proof-of-concept exploits for design-level abuses of trusted Windows and third-party privileged components. This batch targets CrowdStrike Falcon, NVIDIA GPU drivers, Gen Digital Avast, and Kaspersky Endpoint Security, with exploits enabling local SYSTEM escalation, trusted-process code execution, credential-material extraction, or denial of service.
A prolific zero-day researcher publishing proof-of-concept exploits for privilege-escalation flaws in endpoint-security products, including FalconFlank in CrowdStrike Falcon, HardBreacher in Kaspersky Endpoint, and PrettyPrague in Avast.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.