BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-Day Remote Code Execution — Threadlinqs Intelligence
As of 2026-05-30, BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-Day Remote Code Execution is a critical-severity vulnerability threat attributed to BlueHammer and RedSun (China and Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0382 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: VULNERABILITY
Attribution: BlueHammer and RedSun · China and Iran · ESPIONAGE
Two distinct threat actor clusters — BlueHammer (China-nexus espionage) and RedSun (Iran-nexus, IRGC-adjacent) — are actively weaponizing CVE-2026-33825, a critical RCE vulnerability in the Microsoft
CVE-2026-33825 is an out-of-bounds write vulnerability in the Microsoft Malware Protection Engine (MpEngine.dll) affecting all supported versions of Windows Defender Antivirus, Microsoft Defender for Endpoint, Microsoft Security Essentials, and embedded Defender engines shipped with Windows 10, Windows 11, and Windows Server 2016 through 2025. The flaw resides in the archive-handling path of the scan engine: when Defender unpacks a malformed compressed archive (CAB, ZIP, 7Z, or TAR variant with manipulated central-directory offsets), an integer signedness bug causes the engine to write attacker-controlled bytes past the bounds of a fixed-size heap buffer. Because MpEngine runs inside MsMpEng.exe as NT AUTHORITY\SYSTEM, successful exploitation yields immediate SYSTEM-level remote code execution with no user interaction — the mere arrival of a file on disk (email attachment, Teams file share, SMB drop, cached web download, removable media insertion) is sufficient to trigger the on-access scan path.
Microsoft's Security Response Center (MSRC) publicly acknowledged the vulnerability on 2026-04-15 following in-the-wild exploitation detected by Microsoft Threat Intelligence. The engine fix was delivered via automatic Security Intelligence Update definitions version 1.427.325.0 and higher. Because Defender's engine updates are delivered out-of-band from the Patch Tuesday cadence, most auto-updating endpoints received the fix within 48 hours; however, air-gapped, WSUS-staged, or disabled-auto-update environments remain exposed and are the primary targets of continued exploitation.
Two unrelated threat actor clusters are confirmed to have independently discovered or acquired this vulnerability. BlueHammer — tracked by Microsoft as a China-nexus espionage cluster overlapping with CrowdStrike's VANGUARD PANDA and Mandiant's UNC5325 — has used the bug since at least 2026-02 in targeted intrusions against defense-industrial-base (DIB) primes in the United States, Japan, and Australia, and against semiconductor fabs in Taiwan and South Korea. BlueHammer delivers the exploit archive via spear-phishing lures themed around aerospace conference invitations and PDF supply-chain documents, following up post-exploitation with a bespoke Go-language backdoor ("HAMMERFORGE") and side-loaded Cobalt Strike.
RedSun — assessed as IRGC-adjacent and overlapping with Mandiant's APT42 and CrowdStrike's PIONEER KITTEN — began operationalizing CVE-2026-33825 in early 2026-04 against Middle Eastern telecom operators, dissident diaspora organizations, and Israeli defense contractors. RedSun delivers the exploit via compromised WordPress sites using SEO-poisoned search results for trade-publication PDFs, and post-exploits with a custom PowerShell implant ("SUNBEAM") and Meterpreter staged over DNS-over-HTTPS.
Organizations running unpatched Defender engine versions should treat any Internet-reachable or email-accessible endpoint as immediately vulnerable. Detection must focus on anomalous MsMpEng.exe child process creation, unexpected outbound connections from the MsMpEng process, and abnormal memory regions inside MsMpEng indicative of shellcode staging. EDR telemetry showing Defender self-disabling, tamper-protection bypass attempts, or scan-engine crash loops should be treated as high-fidelity exploitation indicators pending investigation.
Weaknesses (CWE)
CWE-787, CWE-120, CWE-125, CWE-190
Target sectors: government, defense-industrial-base, aerospace, semiconductors, telecommunications, financial-services, energy, healthcare, higher-education, dissident-organizations, ngo, media
Target regions: North America, United States, Japan, Australia, Taiwan, South Korea, Israel, United Arab Emirates, Saudi Arabia, Western Europe, United Kingdom
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-33825, T1566, T1566.001, T1189, T1190, T1091, T1203, T1059, T1059.001, T1547, T1547.001