Nightmare-Eclipse is an anonymous exploit developer and public disclosure actor known for rapidly releasing proof-of-concept and, in some cases, weaponizable zero-day material affecting Microsoft Windows security components in 2026. Widely used aliases include Chaotic Eclipse, Dead Eclipse, MSNightmare, and NightmareEclipse. The actor is best known for a sustained series of disclosures targeting Microsoft Defender, Windows Recovery Environment, BitLocker-related workflows, and Windows profile-loading behavior, often without coordinated disclosure and frequently shortly after Patch Tuesday releases. The cluster has been associated with tools and exploit chains including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, GreatXML, and LegacyHive. Reported capabilities across these releases include local privilege escalation to SYSTEM, Defender evasion or disruption, BitLocker and WinRE abuse, and cross-user registry hive loading primitives. Several of the techniques rely less on classic memory corruption and more on chaining legitimate Windows features and trust boundaries, such as Volume Shadow Copy behavior, NTFS junctions and reparse points, opportunistic locks, Cloud Files placeholders, scheduled task execution, offline registry hive modification, Object Manager symbolic links, and profile initialization logic. Operationally, Nightmare-Eclipse has focused on publishing working exploit code and iterative variants at high tempo, with multiple releases over a period of weeks. The actor’s disclosures have centered on design-level and workflow abuses in Microsoft security architecture, especially Microsoft Defender remediation and quarantine paths. Public reporting has linked the cluster to vulnerabilities and exploit chains such as CVE-2026-33825 and CVE-2026-41091, while other releases remained unpatched or lacked CVE assignment at time of disclosure. Some earlier releases were reported as having been observed in real-world intrusion activity after publication. Targeting is best characterized as platform-centric rather than sector-specific: the actor’s work is aimed at Windows endpoints, servers, shared workstations, remote desktop environments, and other Microsoft-dependent enterprise systems. Techniques attributed to the cluster have included privilege escalation, defense impairment, abuse of trusted system services, manipulation of recovery and boot-adjacent workflows, and post-compromise persistence or access-enablement. The actor is not publicly attributed to a nation state, and the real identity remains unknown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
To date, Nightmare Eclipse released over half a dozen zero-days in Microsoft products, including BlueHammer, RedSun, and UnDefend, which have been exploited in attacks...
RedSun CVE-2026-41091 Microsoft Defender Local privilege escalation through link-following behavior Fixed in engine versions at or above 1.1.26040.8; listed in CISA KEV.
UnDefend CVE-2026-45498 Microsoft Defender Antimalware Platform Denial of service / Defender disruption Fixed in platform versions at or above 4.18.26040.7; listed in CISA KEV.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A disclosure actor publishing Windows proof-of-concept techniques that abuse legitimate OS behavior for post-compromise privilege or profile-hijacking scenarios. In this content, it released the LegacyHive PoC, which modifies user registry hives offline, abuses NT Object Manager symbolic links and directories, uses oplocks for timing, and triggers profile loading via CreateProcessWithLogonW.
An earlier 2026 uncoordinated disclosure campaign described as Windows-focused and grievance-driven, referenced here for comparison with Exploitarium.
Publicly releasing unpatched zero-day exploits targeting Microsoft products, including a Windows local privilege escalation exploit dubbed LegacyHive.
A named researcher/activity cluster associated with releasing a toolkit of Windows-focused offensive security tools and primitives, including the LegacyHive registry hive loading primitive affecting the Windows User Profile Service.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.