Nightmare Eclipse is an anonymous exploit developer and uncoordinated vulnerability-disclosure actor active since April 2026. Also known as Chaotic Eclipse, Infinite Nightmare, MSNightmare, and Dead Eclipse, the actor is assessed to be a single researcher using rotating handles. The cluster has publicly released approximately fifteen proof-of-concept tools, predominantly targeting Microsoft Windows, Microsoft Defender, and adjacent Windows security components, with later releases also affecting CrowdStrike Falcon, Kaspersky Endpoint Security, Avast Antivirus, and NVIDIA driver components. The actor’s releases principally abuse design-level interactions among trusted Windows features and endpoint-security remediation functions rather than memory-corruption vulnerabilities. Documented techniques include Cloud Files API abuse, opportunistic-lock race conditions, NTFS redirection, NT Object Manager symbolic-link manipulation, offline registry-hive modification, Windows Defender scan and remediation workflow abuse, and Windows Error Reporting task abuse. Multiple releases provide local privilege-escalation primitives or SYSTEM-level code execution, including exploits associated with CVE-2026-33825 and CVE-2026-41091. Publicly released tools have also demonstrated credential access through local registry-hive exposure, impairment of Microsoft Defender signature updates and security reporting, cross-user registry-hive loading, and post-compromise BitLocker-bypass persistence or data-access techniques. Some Nightmare Eclipse proof-of-concept releases have been independently reproduced, and BlueHammer, RedSun, and UnDefend have been reported as exploited in the wild. The actor’s identity, location, and motivation are not publicly established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
BlueHammer, CVE-2026-33825, was an April 2026 Defender privilege-escalation vulnerability described as a time-of-check to time-of-use race combined with path confusion. CISA added it to the KEV catalog, and ransomware operators were confirmed exploiting it.
The content states that BlueHammer, RedSun, and UnDefend have all been confirmed exploited in the wild.
The content states that BlueHammer, RedSun, and UnDefend have all been confirmed exploited in the wild.
RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM. Microsoft eventually acknowledged the bug... and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A public, uncoordinated vulnerability-research cluster that publishes proof-of-concept tools abusing trusted operating-system and endpoint-security functionality. Its releases concentrate on local privilege-escalation and file-read paths in security products, especially Microsoft Defender. The current ShieldCrash release claims a SYSTEM-level arbitrary-file-read bypass of the ShieldBreak patch, but the published code did not reproduce the claimed read primitive because its redirect chain fails at a timing-sensitive reparse-point stage.
A researcher-linked zero-day disclosure cluster that publicly released four uncoordinated proof-of-concept exploits between August 29 and September 3, 2026, affecting CrowdStrike Falcon Sensor, NVIDIA GPU drivers, Avast Antivirus, and Kaspersky Endpoint Security. The cluster reportedly has fourteen public zero-day releases over five months.
A prolific independent zero-day researcher persona publishing uncoordinated proof-of-concept exploits for design-level abuses of trusted Windows and third-party privileged components. This batch targets CrowdStrike Falcon, NVIDIA GPU drivers, Gen Digital Avast, and Kaspersky Endpoint Security, with exploits enabling local SYSTEM escalation, trusted-process code execution, credential-material extraction, or denial of service.
A prolific zero-day researcher publishing proof-of-concept exploits for privilege-escalation flaws in endpoint-security products, including FalconFlank in CrowdStrike Falcon, HardBreacher in Kaspersky Endpoint, and PrettyPrague in Avast.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.