Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
Cyderes Howler Cell has tracked it since its first release, with prior coverage of BlueHammer, RedSun, RoguePlanet, GreatXML, and most recently LegacyHive in July 2026.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
a non-admin can modify an admin’s classes registry hive and hijack how that account launches applications or COM objects.
LegacyHive abuses this process by modifying the hive offline, redirecting Local AppData into an attacker-controlled NT Object Manager namespace. When the helper account signs in and the modified hive is loaded, applications follow the redirected path, enabling access to resources associated with the target account.
Using native low-level functions such as NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject, the exploit constructs a hidden directory hierarchy and symbolic links designed to redirect critical file path resolutions later in the execution flow.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
Next, the attacker modifies the helper account’s ntuser.dat registry hive while it is offline using Microsoft’s native Registry Offline API. This modification alters the Local AppData environment path so that it points directly into the attacker-controlled Object Manager namespace rather than the user’s authentic profile directory.
With the timing mechanism in place, LegacyHive launches a process as the target user using CreateProcessWithLogonW. The goal is not execution; it is forcing Windows to perform a normal profile load using the LOGON_WITH_PROFILE flag.
successful exploitation would allow non-admin users to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised system.
The attack is staged by a low-privileged user using helper account credentials. Exploitation succeeds only after the helper account authenticates and Windows loads the attacker-modified user profile hive.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
The researcher claims the original exploit did not require additional user credentials and could coerce ProfSvc (and even achieve kernel-level impersonation as NT AUTHORITY\SYSTEM) to load any hive
The attacker triggers a full profile load using CreateProcessWithLogonW configured with the LOGON_WITH_PROFILE flag. This forces Windows to load the tampered hive and activate the redirected paths under the secondary account’s context.
With the timing mechanism in place, LegacyHive launches a process as the target user using CreateProcessWithLogonW. The goal is not execution; it is forcing Windows to perform a normal profile load using the LOGON_WITH_PROFILE flag.
successful exploitation would allow non-admin users to modify the classes registry hive and gain automatic code execution when the admin account logs into a compromised system.
an attacker can overwrite COM objects or shell extensions that load automatically when the administrator logs in, turning the hijacked hive into a persistence and code-execution mechanism that runs with admin privileges during a normal sign-in.
Temporary staging files are cleaned up immediately afterward, but the persistent registry alterations and Object Manager symbolic links remain active.
атакующему заранее понадобится получить локальный доступ, узнать учетные данные обычного пользователя, а также имя учетной записи, которая может принадлежать администратору
The researcher claims the original exploit did not require additional user credentials and could coerce ProfSvc (and even achieve kernel-level impersonation as NT AUTHORITY\SYSTEM) to load any hive
The attacker triggers a full profile load using CreateProcessWithLogonW configured with the LOGON_WITH_PROFILE flag. This forces Windows to load the tampered hive and activate the redirected paths under the secondary account’s context.
a non-admin can modify an admin’s classes registry hive and hijack how that account launches applications or COM objects.
LegacyHive abuses this process by modifying the hive offline, redirecting Local AppData into an attacker-controlled NT Object Manager namespace. When the helper account signs in and the modified hive is loaded, applications follow the redirected path, enabling access to resources associated with the target account.
Using native low-level functions such as NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject, the exploit constructs a hidden directory hierarchy and symbolic links designed to redirect critical file path resolutions later in the execution flow.
Next, the attacker modifies the helper account’s ntuser.dat registry hive while it is offline using Microsoft’s native Registry Offline API. This modification alters the Local AppData environment path so that it points directly into the attacker-controlled Object Manager namespace rather than the user’s authentic profile directory.
The exploit begins by creating a custom directory hierarchy inside the Windows NT Object Manager — a low-level namespace beneath the Win32 API that most applications never interact with. Under: \BaseNamedObjects\Restricted\<UUID> LegacyHive creates a hidden structure that will later be used to redirect Windows path resolution.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior named tool in the same NightmareEclipse exploit cluster, mentioned as historical context and related coverage.
Windows proof-of-concept that abuses profile initialization and offline registry hive modification to redirect Local AppData into an attacker-controlled NT Object Manager namespace. It uses NtCreateDirectoryObjectEx, NtCreateSymbolicLinkObject, offreg.dll, batch oplocks, and CreateProcessWithLogonW with LOGON_WITH_PROFILE to force loading of a tampered user hive and achieve cross-account access/persistent hijack behavior.
A proof-of-concept exploit targeting the Windows User Profile Service (ProfSvc) to achieve local privilege escalation by loading a target user's registry hive into the current user classes root.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.