Nightmare Eclipse is an anonymous exploit developer and public zero-day releaser active in 2026, primarily known for publishing uncoordinated proof-of-concept exploits and abuse techniques targeting Microsoft Windows security components, especially Microsoft Defender, BitLocker- and WinRE-adjacent workflows, and the Windows User Profile Service. Widely used aliases include Nightmare-Eclipse, NightmareEclipse, Chaotic Eclipse, Dead Eclipse, and MSNightmare. The real-world identity of the operator is unknown. The actor is most strongly associated with a rapid series of Windows-focused releases including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, RoguePlanet, GreatXML, MiniPlasma, and LegacyHive. Multiple releases were framed as zero-days or design-level abuses rather than classic memory-corruption exploits. Reported themes across the cluster include local privilege escalation to SYSTEM, Defender workflow abuse, BitLocker and Windows Recovery Environment bypass techniques, and registry hive or profile-loading manipulation. Several of the actor’s disclosures were later patched or assigned CVEs, including BlueHammer, RedSun, and UnDefend, while others remained unpatched or lacked CVE assignment at the time they were discussed. Operationally, Nightmare Eclipse is characterized less as a conventional intrusion set and more as a hostile public exploit publisher whose tooling can be adopted by other threat actors. The actor repeatedly released working or near-working proof-of-concept code without coordinated disclosure or advance vendor notification. Public reporting tied some earlier releases to real-world exploitation after disclosure, increasing downstream risk to defenders even where the original actor’s own intrusion activity was not directly established. Technically, the cluster’s tradecraft consistently emphasizes chaining legitimate Windows features into privilege-boundary violations and workflow abuses. Commonly reported mechanisms include NTFS junctions and other reparse-point abuse, opportunistic locks for race control, Volume Shadow Copy interactions, Cloud Files placeholder behavior, scheduled task abuse, COM activation, offline or cross-user registry hive manipulation, and Windows Recovery Environment state abuse. This pattern suggests strong familiarity with Windows internals, filesystem semantics, profile loading, Defender remediation logic, and post-remediation execution paths. Several releases reportedly avoided reliance on kernel exploitation or memory corruption, instead exploiting design flaws in privileged service workflows. Targeting is overwhelmingly Microsoft-centric. The actor’s published work focused on Windows desktop and server environments, Defender, BitLocker-related recovery paths, and adjacent security components. Some techniques were especially relevant to enterprise environments with shared or multi-user systems, such as Remote Desktop hosts and virtual desktop infrastructure, while others were more applicable to post-compromise persistence, physical-access abuse, or local privilege escalation from an existing foothold. Nightmare Eclipse has been publicly described as a disgruntled or adversarial security researcher engaged in a prolonged dispute with Microsoft over vulnerability handling and disclosure. That dispute became a defining feature of the actor’s public persona and appears to have coincided with the cadence of releases. Platform enforcement actions reportedly removed some repositories and accounts, but mirrored distribution and reposting allowed the tooling to persist across alternative hosting locations and secondary channels. In summary, Nightmare Eclipse is best understood as a high-risk public exploit source centered on Windows security-boundary abuse, especially against Microsoft Defender and related platform trust mechanisms. The actor’s significance lies in rapid publication of technically sophisticated exploit chains, use of multiple aliases within a single researcher cluster, and the demonstrated potential for released tooling to accelerate opportunistic exploitation by other actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
To date, Nightmare Eclipse released over half a dozen zero-days in Microsoft products, including BlueHammer, RedSun, and UnDefend, which have been exploited in attacks...
RedSun CVE-2026-41091 Microsoft Defender Local privilege escalation through link-following behavior Fixed in engine versions at or above 1.1.26040.8; listed in CISA KEV.
UnDefend CVE-2026-45498 Microsoft Defender Antimalware Platform Denial of service / Defender disruption Fixed in platform versions at or above 4.18.26040.7; listed in CISA KEV.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier 2026 uncoordinated disclosure campaign described as Windows-focused and grievance-driven, referenced here for comparison with Exploitarium.
Publicly releasing unpatched zero-day exploits targeting Microsoft products, including a Windows local privilege escalation exploit dubbed LegacyHive.
A named researcher/activity cluster associated with releasing a toolkit of Windows-focused offensive security tools and primitives, including the LegacyHive registry hive loading primitive affecting the Windows User Profile Service.
A researcher/operator releasing a series of public Windows exploit tools and primitives without coordinated disclosure, including LegacyHive and prior tools targeting Windows Defender, BitLocker, and other trusted Windows subsystems. The report characterizes the releases as resembling an operator’s toolkit with multiple paths to SYSTEM, BitLocker bypasses, and telemetry suppression.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.