Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Just hours after Microsoft published its fixes, security researcher “Nightmare Eclipse” published details and proof-of-concept code for a brand-new Windows zero-day dubbed “ShieldBreak.” The flaw bypasses Microsoft’s July patch for CVE-2026-50656 (RoguePlanet) and targets Windows Defender, allowing an attacker to elevate local permissions to SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2025.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
using Windows’ CLFS to swap the identity file and hydration data to a ‘phoneinfo.dll’ file in System32, then running the QueueReporting scheduled task
Condition d’exploitation : Windows Defender doit être activé ; l’exploit est publié sous forme d’application Windows nécessitant une exécution par l’utilisateur
Nightmare Eclipse published the proof-of-concept exploit as a Windows app, requiring the user to run the app to exploit the bug.
In the wer.dll code, there is explicit code to load phoneinfo.dll [which does not exist by default in Windows]. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
ShieldBreak registers a fake cloud sync provider ("Flubber"), creates a placeholder file named "BERLIN" containing EICAR test content, and baits Defender into scanning via a path routed through the Object Manager shadow directory.
During remediation, the exploit rearranges the namespace and uses restart hydration to switch the delivered content from the EICAR bait to the payload DLL.
In the wer.dll code, there is explicit code to load phoneinfo.dll [which does not exist by default in Windows]. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named Windows zero-day exploit that bypasses a prior Microsoft patch and targets Windows Defender to achieve local privilege escalation to SYSTEM.
A local privilege escalation proof-of-concept that abuses Microsoft Defender's scan/remediation pipeline, Cloud Filter API restart hydration, NT Object Manager shadow directories/symlinks, CLFS namespace routing, and Windows Error Reporting task execution to plant a DLL in System32 and achieve NT AUTHORITY\SYSTEM without admin rights, kernel exploitation, or memory corruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.