Activity timeline
Nightmare Eclipse appears in 11 tracked threats between and ; the busiest month was 2026-07 with 4 reports.
ATT&CK techniques observed
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 8 of 11 tracked threats
- T1134 Access Token Manipulation — Privilege Escalationobserved in 7 of 11 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 7 of 11 tracked threats
- T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 6 of 11 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 5 of 11 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 5 of 11 tracked threats
- T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 5 of 11 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 11 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 11 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 3 of 11 tracked threats
- T1003.002 Security Account Manager — Credential Accessobserved in 3 of 11 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 11 tracked threats
- T1012 Query Registry — Discoveryobserved in 3 of 11 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 11 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 11 tracked threats
Tracked threats
- FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoCHIGH
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro RemediationHIGH
- ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for SYSTEM-Level Privilege EscalationCRITICAL
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches InstalledHIGH
- LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive MountingMEDIUM
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)HIGH
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day PoC Released by Nightmare-EclipseHIGH
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection Engine TOCTOU)HIGH
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)HIGH
- Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via cldflt.sys HsmOsBlockPlaceholderAccess / CfAbortHydration (CVE-2020-17103 Regression)HIGH
- YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC (Chaotic/Nightmare Eclipse)CRITICAL