From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain
ID: 4094c051-043b-5981-9d87-87c07d3b30c0
STIX ID: report--4094c051-043b-5981-9d87-87c07d3b30c0
Feed Name: LevelBlue SpiderLabs Blog
LevelBlue SpiderLabs analyzes a series of public zero-day disclosures from an actor calling itself Chaotic/Nightmare Eclipse, focusing on YellowKey — a WinRE TxF transaction-replay PoC (CVE-2026-45585) that enables a SYSTEM command shell and full access to BitLocker-protected volumes on TPM-only Windows systems with ~60 seconds physical access — and MiniPlasma, a local privilege escalation targeting the Cloud Files filter driver; the report details file-structure exploit mechanics, staging vectors (USB/ESP), detection and hunting opportunities, YARA rules, mitigation recommendations (remove autofstx.exe from WinRE BootExecute, consider TPM+PIN), and PoC-specific IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
