Huntress reported a confirmed enterprise intrusion in which an attacker appears to have gained access through a compromised FortiGate SSL VPN account and then deployed publicly available Nightmare-Eclipse tooling on Windows systems. The activity included execution of BlueHammer, RedSun, and UnDefend—tools designed to abuse Windows Defender logic flaws for privilege escalation or defense disruption—alongside hands-on-keyboard reconnaissance and suspicious VPN logins tied to infrastructure geolocated to Russia, Singapore, and Switzerland. Huntress said the privilege-escalation attempts did not appear to succeed in the investigated case, but the tooling was used in a live environment rather than as isolated proof-of-concept testing.
The attacker also deployed a Go-based reverse tunneling utility Huntress tracks as BeigeBurrow, which established outbound connectivity over port 443 to staybud.dpdns[.]org, helping maintain access after the VPN intrusion. Huntress observed suspicious binaries staged in low-privilege, user-writable directories and warned defenders to treat any execution of these tools as urgent incident activity. Microsoft patched BlueHammer in April 2026 as CVE-2026-33825, while RedSun and UnDefend remained unpatched at the time of reporting, underscoring the risk from publicly released exploit tooling being operationalized in real-world attacks.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Huntress published its findings, describing the incident as the first confirmed in-the-wild use of Nightmare-Eclipse tools against a live enterprise environment. The company urged defenders to investigate endpoint, VPN, and tunneling telemetry for the observed artifacts and behaviors.
During the same compromise, Huntress saw hands-on-keyboard activity including enumeration commands and deployment of a Go-based reverse tunneling utility it named BeigeBurrow. The tunnel established outbound connectivity over port 443 to attacker infrastructure, including staybud.dpdns[.]org.
Huntress observed public Nightmare-Eclipse tooling—BlueHammer, RedSun, and UnDefend—executed during a real-world intrusion rather than isolated testing. The tools were staged in low-privilege writable directories, but the privilege-escalation attempts did not appear to succeed.
In the intrusion investigated by Huntress, an attacker appears to have gained unauthorized access using a compromised FortiGate SSL VPN account. Huntress observed suspicious VPN logins tied to the same account from infrastructure geolocated to Russia, Singapore, and Switzerland.
Microsoft patched the Windows Defender-related BlueHammer technique in April 2026 and assigned it CVE-2026-33825. At the time of Huntress's reporting, the related RedSun and UnDefend tools remained unpatched.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcecybersecuritynews.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.