Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Nightmare-Eclipse

As of 2026-09-04, Nightmare-Eclipse is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning vulnerability, zero day. ATT&CK coverage spans 57 techniques across 13 tactics in 5 of 5 tracked threats. Most-observed techniques: T1068 (Exploitation for Privilege Escalation), T1112 (Modify Registry), T1134 (Access Token Manipulation).

Tracked threats
51 critical · 4 high
First seen
2026-05-13
Last seen
2026-09-04
ATT&CK techniques
57across 5 of 5 threats
Related CVEs
0None referenced
5 tracked threat(s) · Categories: VULNERABILITY, ZERO_DAY

Activity timeline

Nightmare-Eclipse appears in 5 tracked threats between and ; the busiest month was 2026-07 with 3 reports.

ATT&CK techniques observed

57 techniques observed across 5 of 5 tracked threats · Stealth (formerly Defense Evasion) (10), Discovery (7), Credential Access (6), Persistence (6), Privilege Escalation (6), Defense Impairment (5)
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 4 of 5 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 3 of 5 tracked threats
  • T1134 Access Token Manipulation — Privilege Escalationobserved in 3 of 5 tracked threats
  • T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 3 of 5 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 2 of 5 tracked threats
  • T1003.002 Security Account Manager — Credential Accessobserved in 2 of 5 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 5 tracked threats
  • T1012 Query Registry — Discoveryobserved in 2 of 5 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 2 of 5 tracked threats
  • T1078.003 Local Accounts — Initial Accessobserved in 2 of 5 tracked threats
  • T1087.001 Local Account — Discoveryobserved in 2 of 5 tracked threats
  • T1106 Native API — Executionobserved in 2 of 5 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 2 of 5 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 2 of 5 tracked threats
  • T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 2 of 5 tracked threats

Tracked threats