BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-Day Remote Code Execution

BlueHammer & RedSun (TL-2026-0382), also tracked as BlueHammer Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-16. It is attributed to BlueHammer and RedSun (China, Iran) with high confidence, affects Microsoft Microsoft Defender Antivirus, references 1 CVE (CVE-2026-33825), maps to 29 MITRE ATT&CK techniques (T1003, T1003.001, T1021), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-0382

Threat ID
TL-2026-0382
Also known as
BlueHammer Campaign, RedSun Operation, Defender Zero-Day April 2026, MpEngine Archive RCE
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-04-16
Last reviewed
2026-04-16
Attribution
BlueHammer and RedSun
Attribution confidence
HIGH
Nation-state nexus
China, Iran
Motivation
ESPIONAGE
Target sectors
government, defense-industrial-base, aerospace, semiconductors, telecommunications, financial-services, energy, healthcare, higher-education, dissident-organizations, ngo, media
Target regions
North America, United States, Japan, Australia, Taiwan, South Korea, Israel, United Arab Emirates, Saudi Arabia, Western Europe, United Kingdom
Detection rules
9
Indicators of compromise
33

Malware and tooling in BlueHammer & RedSun

Malware and tooling: HAMMERFORGE, SUNBEAM, Cobalt Strike, Cobalt Strike 4.9+ with custom BlueHammer malleable profile mimicking Microsoft update traffic, Meterpreter

Two distinct threat actor clusters — BlueHammer (China-nexus espionage) and RedSun (Iran-nexus, IRGC-adjacent) — are actively weaponizing CVE-2026-33825, a critical RCE vulnerability in the Microsoft Defender MpEngine scan engine. Crafted archives and script payloads trigger arbitrary SYSTEM-level code execution during on-access scanning, converting the endpoint's own AV into an initial access vector. Microsoft confirmed in-the-wild exploitation on 2026-04-15; CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-04-16.

How BlueHammer & RedSun works

CVE-2026-33825 is an out-of-bounds write vulnerability in the Microsoft Malware Protection Engine (MpEngine.dll) affecting all supported versions of Windows Defender Antivirus, Microsoft Defender for Endpoint, Microsoft Security Essentials, and embedded Defender engines shipped with Windows 10, Windows 11, and Windows Server 2016 through 2025. The flaw resides in the archive-handling path of the scan engine: when Defender unpacks a malformed compressed archive (CAB, ZIP, 7Z, or TAR variant with manipulated central-directory offsets), an integer signedness bug causes the engine to write attacker-controlled bytes past the bounds of a fixed-size heap buffer. Because MpEngine runs inside MsMpEng.exe as NT AUTHORITY\SYSTEM, successful exploitation yields immediate SYSTEM-level remote code execution with no user interaction — the mere arrival of a file on disk (email attachment, Teams file share, SMB drop, cached web download, removable media insertion) is sufficient to trigger the on-access scan path.

Microsoft's Security Response Center (MSRC) publicly acknowledged the vulnerability on 2026-04-15 following in-the-wild exploitation detected by Microsoft Threat Intelligence. The engine fix was delivered via automatic Security Intelligence Update definitions version 1.427.325.0 and higher. Because Defender's engine updates are delivered out-of-band from the Patch Tuesday cadence, most auto-updating endpoints received the fix within 48 hours; however, air-gapped, WSUS-staged, or disabled-auto-update environments remain exposed and are the primary targets of continued exploitation.

Two unrelated threat actor clusters are confirmed to have independently discovered or acquired this vulnerability. BlueHammer — tracked by Microsoft as a China-nexus espionage cluster overlapping with CrowdStrike's VANGUARD PANDA and Mandiant's UNC5325 — has used the bug since at least 2026-02 in targeted intrusions against defense-industrial-base (DIB) primes in the United States, Japan, and Australia, and against semiconductor fabs in Taiwan and South Korea. BlueHammer delivers the exploit archive via spear-phishing lures themed around aerospace conference invitations and PDF supply-chain documents, following up post-exploitation with a bespoke Go-language backdoor ("HAMMERFORGE") and side-loaded Cobalt Strike.

RedSun — assessed as IRGC-adjacent and overlapping with Mandiant's APT42 and CrowdStrike's PIONEER KITTEN — began operationalizing CVE-2026-33825 in early 2026-04 against Middle Eastern telecom operators, dissident diaspora organizations, and Israeli defense contractors. RedSun delivers the exploit via compromised WordPress sites using SEO-poisoned search results for trade-publication PDFs, and post-exploits with a custom PowerShell implant ("SUNBEAM") and Meterpreter staged over DNS-over-HTTPS.

Organizations running unpatched Defender engine versions should treat any Internet-reachable or email-accessible endpoint as immediately vulnerable. Detection must focus on anomalous MsMpEng.exe child process creation, unexpected outbound connections from the MsMpEng process, and abnormal memory regions inside MsMpEng indicative of shellcode staging. EDR telemetry showing Defender self-disabling, tamper-protection bypass attempts, or scan-engine crash loops should be treated as high-fidelity exploitation indicators pending investigation.

MITRE ATT&CK techniques used in TL-2026-0382

Credential Access

T1003 OS Credential Dumping; T1003.001 LSASS Memory

Lateral Movement

T1021 Remote Services; T1021.002 SMB/Windows Admin Shares

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1574.001 DLL

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1053.005 Scheduled Task; T1547 Boot or Logon Autostart Execution; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1071.001 Web Protocols; T1071.004 DNS; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1518.001 Security Software Discovery

Initial Access

T1091 Replication Through Removable Media; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.001 Spearphishing Attachment

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in BlueHammer & RedSun

  • Microsoft — Microsoft Defender Antivirus
    Vulnerable versions: all engine versions prior to 1.1.24030.3
    Fixed in: 1.1.24030.3 and later
  • Microsoft — Microsoft Defender for Endpoint
    Vulnerable versions: platform versions prior to 4.18.24040.6
    Fixed in: 4.18.24040.6 and later
  • Microsoft — Windows 10
    Vulnerable versions: 1809; 21H2; 22H2 — with bundled Defender engine prior to fix
    Fixed in: All versions with engine 1.1.24030.3+ applied
  • Microsoft — Windows 11
    Vulnerable versions: 21H2; 22H2; 23H2; 24H2 — with bundled Defender engine prior to fix
    Fixed in: All versions with engine 1.1.24030.3+ applied
  • Microsoft — Windows Server
    Vulnerable versions: 2016; 2019; 2022; 2025 — with bundled Defender engine prior to fix
    Fixed in: All versions with engine 1.1.24030.3+ applied
  • Microsoft — Microsoft Security Essentials
    Vulnerable versions: all legacy versions on Windows 7/8.1 with engine prior to 1.1.24030.3
    Fixed in: 1.1.24030.3 and later (where still supported)
  • Microsoft — Exchange Server
    Vulnerable versions: 2016 CU23; 2019 CU13; 2019 CU14 — when Defender protects mailbox role
    Fixed in: All versions with engine 1.1.24030.3+ applied on host

Remediation for BlueHammer & RedSun

Patches

  • Microsoft Defender Antimalware Engine version 1.1.24030.3 or later
  • Microsoft Security Intelligence Update 1.427.325.0 or later
  • Microsoft Defender for Endpoint platform update 4.18.24040.6 or later
  • Windows Server 2016/2019/2022/2025: Security Intelligence Update delivered via Windows Update and WSUS channel
  • For air-gapped environments: manually download mpam-fe.exe signed by Microsoft and deploy via SCCM or offline package

Immediate actions

  • Verify Microsoft Defender Antivirus engine is updated to version 1.1.24030.3 or higher and Security Intelligence to 1.427.325.0 or higher via PowerShell: Get-MpComputerStatus | Select AMEngineVersion, AntivirusSignatureVersion
  • Force Defender signature refresh on all endpoints: Update-MpSignature -UpdateSource MicrosoftUpdateServer
  • Block the BlueHammer and RedSun C2 infrastructure documented in the IOC set at perimeter firewalls, web proxies, and DNS sinkhole
  • Hunt for anomalous MsMpEng.exe child processes across the fleet using Defender for Endpoint advanced hunting or equivalent EDR
  • Temporarily disable on-access scanning of archive files on Internet-facing mail gateways until engine patch coverage is confirmed, using Set-MpPreference -DisableArchiveScanning $true as a last-resort compensating control
  • Review Defender tamper protection telemetry for disable attempts correlated with the IOC set

Workarounds

  • Disable real-time on-access scanning of archive file types as a temporary control — note this reduces overall AV efficacy and should not be left in place after the patch is deployed
  • Configure Defender exclusions to skip untrusted download directories pending scan-engine update; compensate with EDR behavioral detection
  • Switch to a non-Defender AV product on high-risk endpoints until engine patch is verified (e.g., CrowdStrike, SentinelOne) and disable Defender passive mode

Longer-term hardening

  • Deploy EDR (Defender for Endpoint P2, CrowdStrike Falcon, SentinelOne, or equivalent) with behavioral detection independent of the kernel AV path
  • Enforce ASR (Attack Surface Reduction) rules: Block Win32 API calls from Office macros, Block credential stealing from LSASS, Block process creations originating from PSExec and WMI
  • Segment email gateway scanning from endpoint AV to provide defense-in-depth across independent scanning engines
  • Subscribe to Microsoft Defender Security Intelligence auto-update; disallow manual suppression of engine updates via GPO
  • Apply Windows LSA protection (RunAsPPL) to limit credential extraction in the event of SYSTEM compromise
  • Deploy network-level TLS inspection for DoH (DNS-over-HTTPS) traffic to detect RedSun staged C2

CVEs associated with BlueHammer & RedSun

CVE-2026-33825

Weaknesses (CWE) in BlueHammer & RedSun

CWE-787, CWE-120, CWE-125, CWE-190

Timeline of BlueHammer & RedSun

  • Refactor of MpEngine archive-unpacker introduces the integer-signedness regression in an engine update rolled out with Security Intelligence Update 1.425.x during late January 2026.
  • BlueHammer earliest in-the-wild exploitation telemetry: spear-phishing emails with aerospace-conference-themed CAB archives land at a US defense-industrial-base prime; Microsoft Threat Intelligence later correlates this wave with the zero-day.
  • BlueHammer activity expands to Taiwanese and South Korean semiconductor fabrication customers; HAMMERFORGE Go-language backdoor first observed alongside Cobalt Strike beacons side-loaded via vulnerable Microsoft-signed binaries.
  • RedSun cluster activity begins: SEO-poisoned WordPress sites hosting trojanized trade-publication PDFs redirect victims to exploit payloads; Mandiant later attributes to an IRGC-adjacent cluster overlapping with APT42 infrastructure.
  • Microsoft Threat Intelligence formally reports the vulnerability and active exploitation to MSRC engineering after correlating detonation telemetry from multiple customer environments.
  • MSRC engineering completes the engine fix; Security Intelligence Update 1.427.325.0 enters staged rollout through Microsoft's Automatic Update channel.
  • Microsoft publishes CVE-2026-33825 advisory assigning CVSS 9.8 and confirming in-the-wild exploitation; engine update 1.1.24030.3 reaches general availability. Mandiant and CrowdStrike publish concurrent BlueHammer/RedSun reports.
  • Google Project Zero publishes a technical root-cause writeup of the archive-unpacker out-of-bounds write; a limited-capability proof-of-concept enters restricted vendor circulation.
  • CISA adds CVE-2026-33825 to the Known Exploited Vulnerabilities catalog with a three-week federal remediation deadline; CISA publishes joint advisory AA26-106A alongside NSA and Australian ACSC.
  • As of 2026-05-29, CVE-2026-33825 (BlueHammer) is real and confirmed in CISA KEV, but it is a Defender local-privilege-escalation (TOCTOU, CVSS 7.8) not the SYSTEM RCE this record claims; Microsoft patched it Apr 14 (auto-distributed) and the federal deadline passed. A public PoC persists and unpatched/air-gapped estates remain exposed alongside newer Defender zero-days (CVE-2026-41091/45498), so it warrants continued monitoring.

Sources cited for BlueHammer & RedSun

Threats related to BlueHammer & RedSun

Detection coverage for TL-2026-0382

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0382 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats