Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Nightmare-Eclipse Tooling Seen in Real-World Intrusion

a2b6c7a9c4490df70de3cdbfa5fc801a3e1cf6a872749259487e354de2876b7c

TLP:CLEAR
Active

SHA-256 Hash

Description

Activity involving BlueHammer, RedSun, and UnDefend tooling from the Nightmare-Eclipse proof-of-concept repository was observed during a live intrusion investigation. The malicious binaries were staged in user-writable directories including Pictures and Downloads folders, with execution attempts failing despite hands-on-keyboard reconnaissance activities. The threat actor demonstrated unfamiliarity with the tools, misspelling command parameters and attempting non-functional flags. Initial access was traced to compromised FortiGate SSL VPN credentials, with connections originating from Russia, Singapore, and Switzerland. A Go-based tunneling agent dubbed BeigeBurrow was deployed for persistent access, beaconing to attacker infrastructure over port 443 using HashiCorp's yamux library for multiplexed reverse tunneling capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Nightmare-Eclipse Tooling Seen in Real-World Intrusion
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of a2b6c7a9c4490df70de3cdbfa5fc801a3e1cf6a872749259487e354de2876b7c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.