Nightmare-Eclipse Tooling Seen in Real-World Intrusion
ID: 9f05a9a7-1e61-5160-9eeb-11b3474a145a
STIX ID: report--9f05a9a7-1e61-5160-9eeb-11b3474a145a
Feed Name: Huntress Blog
Threat Score
Huntress observed real-world intrusion activity leveraging Nightmare-Eclipse tooling (BlueHammer CVE-2026-33825, RedSun, UnDefend) staged in user-writable directories, likely initiated via compromised FortiGate SSL VPN credentials, with hands-on-keyboard reconnaissance and a Go-based yamux reverse tunnel agent (BeigeBurrow) beaconing to attacker infrastructure; the report provides technical analysis, IoCs, and urgent mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
