BlueHammer is a threat actor or intrusion set associated with a Windows privilege-escalation exploit chain involving abuse of Windows Defender definition update retrieval. Reported activity indicates the actor uses non-standard processes running with low privileges to directly request Defender signature update content via WinINet and to query Defender update infrastructure as part of the exploit chain. A characteristic behavioral artifact is the appearance of Defender signature update packages in the Windows Internet cache under naming patterns produced by HTTP caching rather than by normal Defender components. Observed tradecraft has been mapped to exploitation for privilege escalation, ingress tool transfer, and use of web protocols. BlueHammer is associated with exploitation of CVE-2026-33825. High-confidence reporting in the available material supports only this narrowly defined exploit-related behavior; attribution to a nation state, broader operational history, victimology, sub-groups, or additional aliases is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with an exploit chain that abuses Windows Defender definition update infrastructure as part of privilege escalation activity.
Uses WinINet as a low-privileged user to directly download Windows Defender signature update packages, leaving mpam-fe[1].exe artifacts in INetCache.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.