logo

Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access

ID: 906b97a7-5edd-5d68-9fdc-15a65b9442af

STIX ID: report--906b97a7-5edd-5d68-9fdc-15a65b9442af

Feed Name: cybersecurityNews.com

Threat Score
76/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** Huntress observed a real-world intrusion campaign that began with apparent FortiGate SSL VPN credential abuse and deployed publicly released Nightmare-Eclipse privilege-escalation tooling (BlueHammer, RedSun, UnDefend) alongside a Go-based covert C2/backdoor (BeigeBurrow); BlueHammer is patched (CVE-2026-33825) while RedSun and UnDefend remain unpatched zero-days, investigators confirmed hands-on-keyboard activity, and multiple IoCs (IPs, domain staybud.dpdns.org, filenames, and a BeigeBurrow SHA-256) and mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.