Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Nightmare Eclipse

Also known as:Nightmare-EclipseChaotic EclipseDead EclipseMSNightmareProjectNightcrawler

As of 2026-09-06, Nightmare Eclipse is a threat actor tracked by Threadlinqs Intelligence across 11 threats spanning vulnerability, zero day. Also known as Nightmare-Eclipse, Chaotic Eclipse, Dead Eclipse, MSNightmare. ATT&CK coverage spans 88 techniques across 13 tactics in 11 of 11 tracked threats. Most-observed techniques: T1068 (Exploitation for Privilege Escalation), T1134 (Access Token Manipulation), T1685 (Disable or Modify Tools).

Tracked threats
112 critical · 8 high · 1 medium
First seen
2026-05-13
Last seen
2026-09-06
ATT&CK techniques
88across 11 of 11 threats
Related CVEs
2Referenced by its activity
11 tracked threat(s) · Categories: VULNERABILITY, ZERO_DAY

Activity timeline

Nightmare Eclipse appears in 11 tracked threats between and ; the busiest month was 2026-07 with 4 reports.

ATT&CK techniques observed

88 techniques observed across 11 of 11 tracked threats · Stealth (formerly Defense Evasion) (16), Execution (14), Discovery (10), Persistence (8), Credential Access (7), Privilege Escalation (7)
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 8 of 11 tracked threats
  • T1134 Access Token Manipulation — Privilege Escalationobserved in 7 of 11 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 7 of 11 tracked threats
  • T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 6 of 11 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 5 of 11 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 5 of 11 tracked threats
  • T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 5 of 11 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 11 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 11 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 3 of 11 tracked threats
  • T1003.002 Security Account Manager — Credential Accessobserved in 3 of 11 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 11 tracked threats
  • T1012 Query Registry — Discoveryobserved in 3 of 11 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 3 of 11 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 11 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked Nightmare Eclipse activity