Nightmare-Eclipse
Nightmare Eclipse is a bug hunter/researcher publicly associated with disclosure of multiple Windows zero-days and proof-of-concept releases affecting Microsoft platforms. The content describes Nightmare Eclipse as having published details and, in some cases, full proof-of-concept exploit code for six zero-days, and as having promised additional releases. Known aliases in the provided content are Nightmare Eclipse and Nightmare-Eclipse. The actor is associated with discovery of RedSun (CVE-2026-41091), a local privilege escalation vulnerability in Microsoft Windows Defender’s file remediation workflow. According to the content, RedSun allows an unprivileged user to abuse Defender’s SYSTEM-privileged file operations, NTFS junctions, Cloud Files placeholders, Volume Shadow Copy detection, and opportunistic locks to obtain arbitrary file writes into C:\Windows\System32 and ultimately execute code as NT AUTHORITY\SYSTEM. Nightmare Eclipse is also associated with the public GitHub releases GreenPlasma and YellowKey. GreenPlasma is described as an incomplete Windows local privilege escalation proof of concept or building block involving arbitrary memory section creation and the Windows CTFMON service, but not a complete exploit. YellowKey is described as a Windows login and BitLocker bypass technique requiring physical access, demonstrated against TPM-only BitLocker systems and leveraging WinRE/FsTx behavior to obtain a cmd.exe prompt while the drive is unlocked. The content notes that Nightmare-Eclipse claimed the core YellowKey issue bypasses TPM and PIN configurations, but also states the public proof of concept does not currently demonstrate bypass of TPM and PIN protections. The content does not identify Nightmare Eclipse as a nation-state actor or intrusion set. Instead, it characterizes the actor as a disgruntled bug hunter engaged in a public dispute with Microsoft over vulnerability disclosure and patching.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named bug hunter publicly disclosing multiple Microsoft zero-days and proof-of-concept exploit code, including likely disclosure of the YellowKey vulnerability, in an ongoing dispute with Microsoft.
Named as the discoverer of the RedSun Windows Defender local privilege escalation vulnerability and associated exploit write-up.
Published proof-of-concept offensive tooling on GitHub, including GreenPlasma, described as a building block toward Windows local privilege escalation, and YellowKey, described as a Windows login/BitLocker bypass requiring physical access.
A named actor/researcher associated with publicly releasing the YellowKey BitLocker bypass and partial GreenPlasma privilege-escalation proof-of-concept, exposing unpatched Windows zero-day exploitation details.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.