Activity timeline
Chaotic Eclipse appears in 7 tracked threats between and ; the busiest month was 2026-05 with 2 reports.
ATT&CK techniques observed
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 6 of 7 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 5 of 7 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 5 of 7 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
- T1106 Native API — Executionobserved in 4 of 7 tracked threats
- T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 4 of 7 tracked threats
- T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 3 of 7 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 7 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1134 Access Token Manipulation — Privilege Escalationobserved in 3 of 7 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 3 of 7 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 7 tracked threats
Tracked threats
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)MEDIUM
- LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive MountingMEDIUM
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) PatchedHIGH
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection Engine TOCTOU)HIGH
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)HIGH
- Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via cldflt.sys HsmOsBlockPlaceholderAccess / CfAbortHydration (CVE-2020-17103 Regression)HIGH
- YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC (Chaotic/Nightmare Eclipse)CRITICAL