Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RoguePlanet – race condition zero-day, divulgué en juin 2026, patché sous CVE-2026-50656 le 19 juillet 2026.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the Nightmare-Eclipse disclosure actor has published ShieldBreak — its latest Windows proof of concept (PoC) released shortly after Microsoft's August 2026 Patch Tuesday.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), patched by Microsoft in the July 2026 Defender engine update.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping Technique ID Technique Name Notes T1053.005 Scheduled Task/Job: Scheduled Task QueueReporting triggered via ITaskService::Run()
MITRE ATT&CK Mapping Technique ID Technique Name Notes T1106 Native API NtCreateDirectoryObjectEx, NtCreateSymbolicLinkObject, NtCreateFile
Condition d’exploitation : Windows Defender doit être activé ; l’exploit est publié sous forme d’application Windows nécessitant une exécution par l’utilisateur
Nightmare Eclipse published the proof-of-concept exploit as a Windows app, requiring the user to run the app to exploit the bug.
In the wer.dll code, there is explicit code to load phoneinfo.dll [which does not exist by default in Windows]. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
ShieldBreak registers a fake cloud sync provider ("Flubber"), creates a placeholder file named "BERLIN" containing EICAR test content, and baits Defender into scanning via a path routed through the Object Manager shadow directory.
MITRE ATT&CK Mapping Technique ID Technique Name Notes T1036.005 Masquerading: Match Legitimate Name Fake cloud provider masquerades as sync service
MITRE ATT&CK Mapping Technique ID Technique Name Notes T1070.004 Indicator Removal: File Deletion Post-exploitation cleanup of workdir, WER artifacts
MITRE ATT&CK Mapping Technique ID Technique Name Notes T1218 Signed Binary Proxy Execution wermgr.exe (signed) used as SYSTEM execution vehicle
“An alternate data stream BERLIN:stream is filled with a byte-for-byte copy of ntdll.dll ... loaded to mark the file as in use, and prevent its deletion.”
In the wer.dll code, there is explicit code to load phoneinfo.dll [which does not exist by default in Windows]. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
ShieldBreak proves the point by registering a rogue cloud provider, attaching it to a crafted placeholder file, and using CLFS log manipulation alongside object manager symbolic links to trick Defender’s scanning pipeline into locking a legitimate system file such as phonefo.dll while a malicious substitute is swapped underneath it, ultimately spawning a SYSTEM-level shell.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows local privilege escalation proof of concept that abuses Cloud Files, NT Object Manager namespace manipulation, direct Windows Defender API invocation, and a remediation timing race to coerce Defender into writing an attacker-supplied DLL to C:\Windows\System32\phoneinfo.dll, then achieves SYSTEM execution via the Windows Error Reporting QueueReporting task.
A named Windows zero-day exploit that bypasses a prior Microsoft patch and targets Windows Defender to achieve local privilege escalation to SYSTEM.
Windows local privilege-escalation exploit and patch bypass targeting a CWE-59 path-resolution flaw in Microsoft Defender remediation. It manipulates Cloud Files placeholders and Object Manager links to cause Defender, running as SYSTEM, to write a malicious DLL as phoneinfo.dll; Windows Error Reporting then loads it, yielding a SYSTEM shell in the attacking user's session.
A local privilege escalation proof-of-concept that abuses Microsoft Defender's scan/remediation pipeline, Cloud Filter API restart hydration, NT Object Manager shadow directories/symlinks, CLFS namespace routing, and Windows Error Reporting task execution to plant a DLL in System32 and achieve NT AUTHORITY\SYSTEM without admin rights, kernel exploitation, or memory corruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.