logo

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

ID: 9f05a9a7-1e61-5160-9eeb-11b3474a145a

STIX ID: report--9f05a9a7-1e61-5160-9eeb-11b3474a145a

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-28

...
...

Huntress observed real-world intrusion activity leveraging Nightmare-Eclipse tooling (BlueHammer CVE-2026-33825, RedSun, UnDefend) staged in user-writable directories, likely initiated via compromised FortiGate SSL VPN credentials, with hands-on-keyboard reconnaissance and a Go-based yamux reverse tunnel agent (BeigeBurrow) beaconing to attacker infrastructure; the report provides technical analysis, IoCs, and urgent mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.