Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access
ID: 906b97a7-5edd-5d68-9fdc-15a65b9442af
STIX ID: report--906b97a7-5edd-5d68-9fdc-15a65b9442af
Feed Name: cybersecurityNews.com
**Executive Summary:** Huntress observed a real-world intrusion campaign that began with apparent FortiGate SSL VPN credential abuse and deployed publicly released Nightmare-Eclipse privilege-escalation tooling (BlueHammer, RedSun, UnDefend) alongside a Go-based covert C2/backdoor (BeigeBurrow); BlueHammer is patched (CVE-2026-33825) while RedSun and UnDefend remain unpatched zero-days, investigators confirmed hands-on-keyboard activity, and multiple IoCs (IPs, domain staybud.dpdns.org, filenames, and a BeigeBurrow SHA-256) and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
