Threat reportZero-DayTL-2026-0512

YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC (Chaotic/Nightmare Eclipse)

criticalACTIVE

YellowKey & GreenPlasma (TL-2026-0512), also tracked as YellowKey, is a critical-severity zero-day vulnerability scored CVSS 9.3, first published 2026-05-13. It is attributed to Chaotic Eclipse with high confidence, affects Microsoft Windows 11, maps to 19 MITRE ATT&CK techniques (T1003, T1005, T1006), and is covered by 9 detection rules and 24 indicators of compromise.

CVSS
9.3/10Critical
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1Chaotic Eclipse
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-0512

Threat ID
TL-2026-0512
Also known as
YellowKey, GreenPlasma, Nightmare Eclipse May 2026 disclosure, Windows BitLocker WinRE FsTx bypass
Severity
CRITICAL
CVSS
9.3 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
ZERO_DAY
First published
Last reviewed
Attribution
Chaotic Eclipse
Attribution confidence
HIGH
Motivation
HACKTIVISM
Target sectors
government, financial, healthcare, defense, energy, technology, education, legal, manufacturing, telecom, msp, law-enforcement
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
24

Malware and tooling in YellowKey & GreenPlasma

Malware and tooling: BlueHammer (CVE-2026-33825), GreenPlasma, RedSun, UnDefend, YellowKey

How YellowKey & GreenPlasma works

On May 13, 2026, the researcher Chaotic Eclipse (GitHub: Nightmare-Eclipse) published two unpatched Windows zero-day exploits as a protest against Microsoft's vulnerability handling. YellowKey is a BitLocker bypass affecting Windows 11 and Windows Server 2022/2025 that abuses Windows Recovery Environment (WinRE) NTFS transaction-log replay to delete X:\Windows\System32\winpeshl.ini, causing WinRE to launch cmd.exe with full read/write access to the still-unlocked BitLocker volume. GreenPlasma is a Local Privilege Escalation flaw ("Windows CTFMON Arbitrary Section Creation EoP") in which an unprivileged user creates arbitrary memory-section objects inside SYSTEM-writable directory objects, enabling manipulation of privileged services to obtain a SYSTEM shell. Kevin Beaumont independently validated YellowKey; Will Dormann (Analygence) reproduced the USB variant and identified the NTFS log-replay root cause. TPM-only and TPM+PIN BitLocker configurations are both bypassable. No CVEs are assigned and no Microsoft patch exists.

OVERVIEW On May 13, 2026, the security researcher who self-identifies as "Chaotic Eclipse" (GitHub handle Nightmare-Eclipse) publicly released proof-of-concept exploit code for two unpatched Microsoft Windows zero-day vulnerabilities — YellowKey, a BitLocker authentication/encryption bypass, and GreenPlasma, a kernel-assisted local privilege escalation. The disclosure was performed without coordinated vulnerability disclosure (CVD); the researcher cites dissatisfaction with Microsoft's bug-handling and has publicly promised to leak additional Windows exploits, including "a big surprise" for the next Patch Tuesday. The repository (github.com/Nightmare-Eclipse/YellowKey) reached 999 stars and 225 forks within hours of publication.

The disclosure follows the same actor's prior releases: BlueHammer (CVE-2026-33825, Microsoft Defender LPE via TOCTOU on the file-remediation engine, patched April 2026), RedSun (a sibling Defender LPE that was silently patched), and UnDefend. Huntress Labs (May 2026) reported all three of those prior PoCs were observed in real-world intrusions within weeks of disclosure, making operational weaponization of YellowKey and GreenPlasma highly probable.

YELLOWKEY — TECHNICAL ANALYSIS (BITLOCKER BYPASS) YellowKey exploits a logic flaw in the Windows Recovery Environment (WinRE) boot image that is not present in the equivalent components of the mainline OS install — the researcher and several independent reviewers (Will Dormann/Analygence, Kevin Beaumont) note that the same code in normal Windows lacks the exploitable behavior, leading the researcher to credit, sarcastically, "MORSE, MSTIC, and Microsoft GHOST" and to describe the component as an apparent backdoor.

Root cause (per Will Dormann's reproduction): WinRE, on boot, enumerates attached volumes and replays NTFS Transactional Resource Manager (TxR) logs found in each volume's "\System Volume Information\FsTx\<GUID>\" directory. The exploit ships a precrafted FsTx directory (GUID 95F62703B343F111A92A005056975458) containing FsTxLogs/ and FsTxTemp/ subdirectories whose log records, when replayed, cause WinRE's RAM disk image (X:\) to drop or overwrite X:\Windows\System32\winpeshl.ini. Because winpeshl.ini specifies the recovery interface to launch, its absence causes WinRE to fall back to launching cmd.exe — and crucially, by this point WinRE has already invoked the TPM-sealed VMK and mounted the BitLocker volume read/write at C:\. The attacker is dropped into an unrestricted SYSTEM command prompt with full access to the plaintext BitLocker volume — no recovery key, no PIN, no unlock prompt.

Exploitation procedure (USB variant): 1. Attacker formats a FAT32/NTFS USB stick. 2. Copies the YellowKey FsTx folder verbatim to <USB>:\System Volume Information\FsTx\95F62703B343F111A92A005056975458\. 3. Inserts USB into the target machine (powered on at the lock screen, or off). 4. Holds Shift and clicks Restart -> Troubleshoot -> Advanced -> WinRE. 5. Releases Shift on click; immediately holds CTRL and keeps holding it through reboot. 6. If timing aligns, WinRE drops to a cmd.exe shell with the BitLocker C:\ volume mounted.

Exploitation procedure (EFI variant — bypasses "no removable media" GPO): 1. Attacker removes the disk from the target machine. 2. Mounts the EFI System Partition on a controlled workstation. 3. Writes the FsTx folder to the EFI partition (path not publicly disclosed in full). 4. Re-installs the disk and boots normally; WinRE replay path is hit during the next recovery cycle. Will Dormann reproduced the USB variant but did not reproduce the EFI variant in his testbed.

TPM+PIN: Chaotic Eclipse states the exploit "still works in TPM+PIN environments" but withheld the TPM+PIN trigger variant. The disclosed USB/EFI variant is reported to work against TPM-only configurations, which are the Windows 11 default.

GREENPLASMA — TECHNICAL ANALYSIS (CTFMON ARBITRARY SECTION CREATION LPE) GreenPlasma is described by the researcher as a "Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability." The underlying primitive: an unprivileged user can create kernel section objects (Section, \KnownDlls-style mapped memory) inside directory objects in the NT object namespace that are writable by SYSTEM but should not be writable (or attacker-controllable) from a Medium IL token. ctfmon.exe (and other SYSTEM services that resolve handles by name in the object namespace) then opens the attacker-planted section, mapping attacker-controlled memory into a privileged context. A complete exploit chains the section-creation primitive to hijack a SYSTEM service's code or data path, producing a SYSTEM shell.

The published PoC is intentionally incomplete — the final "smart-enough" pivot to a full SYSTEM shell is withheld but is described as straightforward for capable attackers. Independent SOC telemetry (Huntress) has historically observed Nightmare-Eclipse PoCs operationalized within days of release; defenders should assume a full chain is in private circulation.

IMPACT YellowKey collapses the trust boundary that Windows full-disk encryption is designed to enforce. Any attacker with brief physical access to a Windows 11 or Server 2022/2025 endpoint can read, modify, or implant on the entire encrypted volume — extracting Active Directory credentials (SAM, NTDS.DIT on DCs), browser/credential vaults (DPAPI material), Outlook OST, source code, certificate stores — without ever seeing a recovery-key or PIN prompt. The "evil maid" threat model that BitLocker was specifically designed to resist is fully realized. Combined with GreenPlasma, an attacker who lands on the box with any user-level foothold then has a reliable path to SYSTEM, completing local compromise.

MITIGATIONS (No vendor patch as of 2026-05-13) - Enforce Pre-Boot authentication (TPM+PIN+USB key, or BitLocker network unlock with strict policy) — note: researcher states TPM+PIN is also bypassable; treat as defense-in-depth only. - Block USB mass-storage at the boot/firmware level via UEFI Secure Boot DBX, vendor BIOS USB lockdown, or physical port disable for high-value endpoints. - Disable WinRE on production endpoints where not required: reagentc /disable; bcdedit /set {default} recoveryenabled No; remove or replace the recovery partition. Document that this also disables push-button reset/repair. - Enable VBS/HVCI and Credential Guard so post-bypass SAM/LSA secret extraction is degraded. - Monitor for unauthorized boots into WinRE (Event ID 7036/7045, BCD writes, recoveryenabled toggles). - Hunt for the FsTx GUID 95F62703B343F111A92A005056975458 on attached volumes and EFI partitions. - For GreenPlasma: enforce restricted user-mode handle access on \BaseNamedObjects and \Sessions\<id>\BaseNamedObjects; deploy EDR detections for kernel section objects opened by ctfmon.exe and other SYSTEM IME components from unexpected paths.

ATTRIBUTION & DISCLOSURE POSTURE The researcher "Chaotic Eclipse / Nightmare-Eclipse" is positioned as a hacktivist disclosing for protest, not a financially motivated criminal actor. However, the threat-actor concern is not the researcher — it is downstream weaponization: Huntress confirmed BlueHammer/RedSun/UnDefend were operationalized within weeks. Defenders should plan for in-the-wild exploitation of YellowKey and GreenPlasma within the same horizon.

MITRE ATT&CK techniques used in TL-2026-0512

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1006 Direct Volume Access; T1070 Indicator Removal

Execution

T1059 Command and Scripting Interpreter; T1106 Native API

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1091 Replication Through Removable Media; T1200 Hardware Additions

Impact

T1490 Inhibit System Recovery; T1565 Data Manipulation

Persistence

T1542 Pre-OS Boot

defense-impairment

T1556 Modify Authentication Process; T1601 Modify System Image

Affected products and versions in YellowKey & GreenPlasma

  • Microsoft — Windows 11
    Vulnerable versions: 21H2; 22H2; 23H2; 24H2
  • Microsoft — Windows Server
    Vulnerable versions: 2022; 2025
  • Microsoft — Windows Recovery Environment (WinRE)
    Vulnerable versions: WinRE image shipped with Windows 11 21H2 through 24H2; WinRE image shipped with Windows Server 2022 and 2025
  • Microsoft — BitLocker Drive Encryption
    Vulnerable versions: TPM-only configurations on Windows 11 and Server 2022/2025; TPM+PIN configurations on Windows 11 and Server 2022/2025 (per researcher claim; variant withheld)

Remediation for YellowKey & GreenPlasma

Patches

  • No vendor patch available as of 2026-05-13. Microsoft has acknowledged investigation under coordinated vulnerability disclosure; monitor MSRC for an out-of-band update before the next Patch Tuesday.

Immediate actions

  • Disable Windows Recovery Environment on production endpoints where not required: reagentc /disable and bcdedit /set {default} recoveryenabled No.
  • Enforce BIOS/UEFI USB boot lockdown and Secure Boot on all endpoints; physically disable USB ports on high-value workstations and servers.
  • Hunt all attached volumes, USB media, and EFI System Partitions for the FsTx GUID directory 95F62703B343F111A92A005056975458 (FsTxLogs/, FsTxTemp/ subfolders).
  • Enable BitLocker Pre-Boot Authentication (TPM+PIN minimum, TPM+PIN+Startup Key preferred) as defense-in-depth, acknowledging the researcher claims a TPM+PIN bypass variant exists.
  • Restrict physical access to BitLocker-protected endpoints; treat any unattended-access incident as a potential compromise.
  • Audit BCD recovery configuration; alert on changes to recoveryenabled and on unexpected boots into the recovery partition.

Workarounds

  • Remove or replace WinRE: reagentc /disable; delete the Recovery partition (note: disables push-button reset and Windows recovery features).
  • GPO: Computer Configuration -> Administrative Templates -> System -> Removable Storage Access -> Deny all access for Removable Storage Devices (mitigates USB variant, not EFI variant).
  • Apply UEFI firmware boot order restrictions disallowing boot from removable media and enforcing Secure Boot user mode.

Longer-term hardening

  • Enable VBS, HVCI, and Credential Guard so credential material on the volume is protected after a YellowKey bypass.
  • Deploy EDR with kernel-section-object telemetry to detect GreenPlasma-style CTFMON section hijacks (Sysmon EventID 7/11 plus object-namespace handle audit).
  • Implement remote attestation of WinRE image integrity via Windows Defender System Guard or third-party measured-boot platform.
  • Adopt Network Unlock with strict policy that requires domain network presence to release the VMK, removing offline single-USB-attack viability.
  • Maintain incident-response playbook assuming any lost/stolen Windows 11 or Server 2022/2025 device with WinRE present is fully compromised — including SAM, NTDS.DIT, DPAPI, certificate stores.

Weaknesses (CWE) in YellowKey & GreenPlasma

CWE-284, CWE-269, CWE-668, CWE-274, CWE-732

Timeline of YellowKey & GreenPlasma

  • Chaotic Eclipse / Nightmare-Eclipse publicly releases BlueHammer PoC (later CVE-2026-33825), a TOCTOU LPE in Microsoft Defender file-remediation; RedSun and UnDefend variants follow.
  • Microsoft assigns CVE-2026-33825 to BlueHammer and acknowledges active exploitation; RedSun is silently patched in the same cycle.
  • Huntress publishes telemetry showing BlueHammer, RedSun, and UnDefend PoCs operationalized in real-world intrusions, establishing high probability of rapid weaponization of any future Nightmare-Eclipse disclosure.
  • Nightmare-Eclipse YellowKey repository is created on GitHub; first commits stage the FsTx GUID directory 95F62703B343F111A92A005056975458 with FsTxLogs and FsTxTemp subfolders.
  • Threadlinqs Intelligence Platform publishes TL-2026-0512 with full exploit chain, MITRE mapping, IOCs, and detection coverage.
  • Microsoft acknowledges receipt and commits to investigation under coordinated vulnerability disclosure but issues no patch and assigns no CVE for YellowKey or GreenPlasma.
  • BleepingComputer, The Register, Tom's Hardware, XDA Developers, Cybernews, and SecurityOnline publish coverage; researcher repository reaches 999 stars and 225 forks within hours.
  • Kevin Beaumont independently validates YellowKey; Will Dormann (Analygence) reproduces the USB variant and identifies NTFS Transactional Resource Manager (TxR) log replay deleting X:\Windows\System32\winpeshl.ini as the root cause.
  • Public PoC and walkthrough for YellowKey (BitLocker bypass) and GreenPlasma (CTFMON Arbitrary Section Creation LPE) released on Nightmare-Eclipse GitHub; researcher cites Microsoft handling as motivation and promises further leaks.
  • As of 2026-05-29, YellowKey is now CVE-2026-45585 (CVSS 6.8) but Microsoft has shipped only a temporary mitigation script (May 20-21, remove autofstx.exe / use TPM+PIN) with NO permanent patch yet, and GreenPlasma remains unpatched. Public PoC persists, the Nightmare-Eclipse actor stays active threatening more leaks, and sibling tooling is already exploited in the wild, so this is live.

Sources cited for YellowKey & GreenPlasma

Detection coverage for TL-2026-0512

As of 2026-05-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0512 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats