Activity timeline
NightmareEclipse appears in 4 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 3 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
- T1069 Permission Groups Discovery — Discoveryobserved in 2 of 4 tracked threats
- T1074.001 Local Data Staging — Collectionobserved in 2 of 4 tracked threats
- T1078.003 Local Accounts — Initial Accessobserved in 2 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 2 of 4 tracked threats
- T1106 Native API — Executionobserved in 2 of 4 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 2 of 4 tracked threats
- T1134 Access Token Manipulation — Privilege Escalationobserved in 2 of 4 tracked threats
- T1546 Event Triggered Execution — Persistenceobserved in 2 of 4 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movementobserved in 2 of 4 tracked threats
- T1564 Hide Artifacts — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
- T1649 Steal or Forge Authentication Certificates — Credential Accessobserved in 2 of 4 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 4 tracked threats
Tracked threats
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space ExhaustionMEDIUM
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World IntrusionsCRITICAL
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry Hive LoadingHIGH
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public PoC Bypasses Fully Patched SystemsHIGH