BlueHammer is a publicly released Windows local privilege escalation exploit that targets Microsoft Defender and enables an attacker with an existing low-privilege foothold to obtain elevated access, up to NT AUTHORITY\SYSTEM on affected systems. It was associated with the researcher cluster using the aliases Nightmare-Eclipse and Chaotic Eclipse and was later tracked as CVE-2026-33825. Microsoft patched the issue in April 2026, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities catalog.
BlueHammer abuses a time-of-check/time-of-use race condition in Defender’s privileged update and remediation workflow rather than relying on memory corruption or a kernel vulnerability. Reported exploit chains use legitimate Windows components including Volume Shadow Copy Service, Cloud Files functionality, opportunistic locks, and path redirection techniques to turn Defender’s SYSTEM-level operations into a privileged file-read primitive. The primary outcome described for BlueHammer is exposure of protected registry hives, especially the SAM hive, allowing extraction of local account credential material such as NTLM hashes.
Operationally, BlueHammer has been described as using the leaked credential material to compromise a local administrator account, briefly alter a high-value local account password, authenticate, and then spawn elevated execution before restoring the original credential state to reduce visibility. Some reporting characterizes the post-read stage as pass-the-hash-based escalation, while other reporting describes temporary password replacement followed by authenticated shell or service creation; the consistent high-confidence point is that the exploit is used to convert a low-privilege foothold into administrative or SYSTEM-level execution through access to protected local credential data.
BlueHammer has been observed alongside other Nightmare-Eclipse tools such as RedSun and UnDefend in real-world intrusion activity. Reported intrusions used compromised FortiGate VPN access for initial entry, followed by reconnaissance and attempted post-compromise privilege escalation with BlueHammer. The exploit targets Windows systems and is relevant to enterprise environments that rely on Microsoft Defender, particularly where attackers already possess user-level execution and seek rapid local escalation without deploying kernel exploits.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlueHammer turned the race into a privileged file read and used it to access the SAM hive.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
This enables an attacker to read the SAM database, decrypt NTLM password hashes, take over a local administrator account, and spawn a SYSTEM-level shell, while restoring the original hash to avoid detection.
Threat actors were observed deploying the tools under disguised filenames such as FunnyApp.exe, gaining initial access through compromised FortiGate VPN credentials before pivoting to Defender exploits for privilege escalation.
It uses the samlib.dll function SamiChangePasswordUser to forcefully change a local Administrator's password to an attacker-controlled value ... Finally, to hide its tracks, it uses SamiChangePasswordUser again to restore the original NTLM password hash.
MITRE ATT&CK: T1068 - Exploitation for Privilege Escalation (Tactic: Privilege Escalation). MiniPlasma - локальный эксплойт... именно на этапе перехода от ограниченного пользователя к полному контролю над хостом LPE до SYSTEM решает
Threat actors were observed deploying the tools under disguised filenames such as FunnyApp.exe, gaining initial access through compromised FortiGate VPN credentials before pivoting to Defender exploits for privilege escalation.
It uses the samlib.dll function SamiChangePasswordUser to forcefully change a local Administrator's password to an attacker-controlled value ... Finally, to hide its tracks, it uses SamiChangePasswordUser again to restore the original NTLM password hash.
It logs in as that Administrator using the new password (LogonUserEx). It duplicates the security token of the Administrator, assigns it SYSTEM integrity levels...
It duplicates the security token of the Administrator, assigns it SYSTEM integrity levels, and uses CreateService to create a malicious temporary Windows Service.
в Windows Server код сработал не так, как было задумано... повышает права не до уровня SYSTEM, а с уровня обычного пользователя до администратора с повышенными привилегиями (то есть обходит механизм, который обычно требует от пользователя вручную подтвердить операцию, запрашивающую полный доступ).
Threat actors were observed deploying the tools under disguised filenames such as FunnyApp.exe, gaining initial access through compromised FortiGate VPN credentials before pivoting to Defender exploits for privilege escalation.
BlueHammer: Privileged File Read ... Leaks NTLM hashes, takes over a local admin account via pass-the-hash, and escalates to SYSTEM.
This enables an attacker to read the SAM database, decrypt NTLM password hashes, take over a local administrator account, and spawn a SYSTEM-level shell, while restoring the original hash to avoid detection.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior named tool in the same NightmareEclipse exploit cluster, mentioned as historical context and related coverage.
A Defender local privilege escalation primitive to SYSTEM, cited as one of several tools in the Nightmare-Eclipse cluster.
An earlier exploit in the same Nightmare-Eclipse cluster targeting Microsoft Defender or adjacent Windows security components; the content notes it has moved beyond proof-of-concept and appeared in real-world intrusion chains.
A Windows Defender exploit tool that abuses a TOCTOU race condition in Defender’s threat remediation engine to achieve SYSTEM-level privilege escalation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.