Researcher MSNightmare (also known as Nightmare-Eclipse) released BigDiskBuster, an experimental proof of concept designed to prevent Microsoft Defender Antivirus from completing platform and security-intelligence updates. The technique monitors Defender update directories, consumes available disk capacity with hidden temporary files, and locks MRT.exe using restrictive file-sharing permissions, potentially interrupting update staging, installation, or rollback and leaving Defender enabled but increasingly reliant on outdated detection content.
The claimed impact across supported Windows versions has not been independently verified, and the released code is reportedly buggy. Security teams should investigate unexplained free-space depletion, hidden files in user Temp directories, persistent handles on MRT.exe, and repeated Defender update failures; 0x80070643 alone is a generic error and does not prove exploitation. Suspected hosts should be validated with preserved telemetry, malicious processes terminated, disk capacity restored, and Defender updated from a trusted source.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Security researcher MSNightmare (Nightmare-Eclipse) released BigDiskBuster, an experimental proof of concept designed to disrupt Microsoft Defender Antivirus platform and security-intelligence updates by exhausting disk space and locking MRT.exe. The researcher supplied a test screenshot showing a Defender update failure, though the technique's effectiveness and cross-version compatibility were not independently verified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.