Chaotic Eclipse, also referred to as Nightmare Eclipse, is an anonymous security researcher or exploit developer persona associated with a series of public Microsoft Windows zero-day and proof-of-concept disclosures beginning in 2026. The activity is notable for publishing practical local and physically assisted attack techniques against native Windows security mechanisms rather than for documented intrusion operations, victimization campaigns, or financially motivated extortion. Publicly attributed disclosures linked to this persona include YellowKey, GreenPlasma, MiniPlasma, and UnDefend. YellowKey was assigned CVE-2026-45585 and is a BitLocker security feature bypass affecting TPM-only deployments on supported Windows platforms. The technique abuses Windows Recovery Environment behavior to obtain a SYSTEM-level shell after the protected volume has been unlocked by the TPM, enabling post-boot access without the user’s password or recovery key when brief physical access is available. GreenPlasma was presented as a privilege-escalation technique leveraging Windows object manager behavior and trusted path redirection. MiniPlasma was described as a local privilege-escalation method targeting the Windows Cloud Files filter driver through a race condition related to the code path previously associated with CVE-2020-17103. UnDefend was described publicly as a Microsoft Defender zero-day technique capable of preventing signature updates from a standard user context without administrator privileges, although some details were reportedly withheld and no CVE assignment was noted. Across these disclosures, Chaotic Eclipse demonstrates strong capability in Windows internals, local privilege escalation, security feature bypass, and defense impairment. The techniques emphasize abuse of legitimate operating system functionality, recovery-environment manipulation, object manager behavior, race conditions, and low-artifact execution paths. Available information supports characterization as a public exploit-disclosure persona focused on exposing Windows security weaknesses; it does not support high-confidence attribution to a nation state, ransomware operation, or established intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.