Visualização normal

Antes de ontemSpiderLabs Blog

Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs

9 de Setembro de 2026, 09:37

In our previous blog, we explored a series of disclosures from the leak persona Nightmare-Eclipse that focused heavily on Microsoft's ecosystem, including Windows Defender, Cloud Files, and core operating system functionality.

Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

28 de Agosto de 2026, 11:00

This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account.

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking

19 de Agosto de 2026, 12:40

Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and LegacyHive, the Nightmare-Eclipse disclosure actor has published ShieldBreak — its latest Windows proof of concept (PoC) released shortly after Microsoft's August 2026 Patch Tuesday.

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

27 de Julho de 2026, 11:07

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC) released shortly after Microsoft's July 2026 Patch Tuesday.

  • ✇SpiderLabs Blog
  • Still Circling: Blind Eagle's Toolkit Keeps Evolving Serhii Melnyk
    In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.
     

Still Circling: Blind Eagle's Toolkit Keeps Evolving

17 de Julho de 2026, 10:57

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.

RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse

17 de Junho de 2026, 15:58

Following our previous research, LevelBlue SpiderLabs continued monitoring a series of Windows security component disclosures published under multiple online aliases, including Nightmare-Eclipse, Chaotic Eclipse, Dead Eclipse, and most recently MSNightmare.

From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain

22 de Maio de 2026, 11:00

Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has tracked a series of public zero-day disclosures targeting Microsoft Windows, attributed to an anonymous actor operating under the names Chaotic Eclipse and Nightmare Eclipse. The activity spans multiple areas of the Windows security model, including recent disclosures such as GreenPlasma, MiniPlasma, and YellowKey.

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems

23 de Abril de 2026, 11:00

LevelBlue SpiderLabs’ Cyber Threat Intelligence Team continues to observe a progressive convergence between traditional cybercrime activity and attacks targeting cryptocurrency users.

❌
❌