Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Chaotic Eclipse

Also known as:Nightmare EclipseNightmare-Eclipse

As of 2026-09-22, Chaotic Eclipse is a threat actor tracked by Threadlinqs Intelligence across 7 threats spanning vulnerability, zero day. Also known as Nightmare Eclipse, Nightmare-Eclipse. ATT&CK coverage spans 78 techniques across 13 tactics in 7 of 7 tracked threats. Most-observed techniques: T1068 (Exploitation for Privilege Escalation), T1082 (System Information Discovery), T1685 (Disable or Modify Tools).

Tracked threats
71 critical · 4 high · 2 medium
First seen
2026-05-13
Last seen
2026-09-22
ATT&CK techniques
78across 7 of 7 threats
Related CVEs
3Referenced by its activity
7 tracked threat(s) · Categories: VULNERABILITY, ZERO_DAY

Activity timeline

Chaotic Eclipse appears in 7 tracked threats between and ; the busiest month was 2026-05 with 2 reports.

ATT&CK techniques observed

78 techniques observed across 7 of 7 tracked threats · Stealth (formerly Defense Evasion) (13), Execution (10), Discovery (8), Initial Access (6), Persistence (6), Privilege Escalation (6)
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 6 of 7 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 5 of 7 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 5 of 7 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
  • T1106 Native API — Executionobserved in 4 of 7 tracked threats
  • T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 4 of 7 tracked threats
  • T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 3 of 7 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 7 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1134 Access Token Manipulation — Privilege Escalationobserved in 3 of 7 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 3 of 7 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 7 tracked threats

Tracked threats

Related CVEs

3 CVEs referenced by tracked Chaotic Eclipse activity