Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-07

NightmareEclipse

As of 2026-09-22, NightmareEclipse is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning vulnerability. ATT&CK coverage spans 54 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1033 (System Owner/User Discovery), T1068 (Exploitation for Privilege Escalation), T1005 (Data from Local System).

Tracked threats
41 critical · 2 high · 1 medium
First seen
2026-07-17
Last seen
2026-09-22
ATT&CK techniques
54across 4 of 4 threats
Related CVEs
5Referenced by its activity
4 tracked threat(s) · Categories: VULNERABILITY

Activity timeline

NightmareEclipse appears in 4 tracked threats between and ; the busiest month was 2026-07 with 2 reports.

ATT&CK techniques observed

54 techniques observed across 4 of 4 tracked threats · Stealth (formerly Defense Evasion) (9), Persistence (7), Discovery (6), Credential Access (5), Execution (5), Privilege Escalation (5)
  • T1033 System Owner/User Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 3 of 4 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
  • T1069 Permission Groups Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1074.001 Local Data Staging — Collectionobserved in 2 of 4 tracked threats
  • T1078.003 Local Accounts — Initial Accessobserved in 2 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1106 Native API — Executionobserved in 2 of 4 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 2 of 4 tracked threats
  • T1134 Access Token Manipulation — Privilege Escalationobserved in 2 of 4 tracked threats
  • T1546 Event Triggered Execution — Persistenceobserved in 2 of 4 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 2 of 4 tracked threats
  • T1564 Hide Artifacts — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1649 Steal or Forge Authentication Certificates — Credential Accessobserved in 2 of 4 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 4 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked NightmareEclipse activity