‼️ Nightmare-Eclipse has just released two new GitHub repositories... Same user behind RedSun, Un...
Threat actor releases two new exploitation tools: YellowKey (BitLocker bypass) and GreenPlasma (Windows privilege
Run Windows CTFMON?
Get an email when a reviewed story names Windows CTFMON, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
A threat actor known as Nightmare-Eclipse, linked to previous malware campaigns RedSun, UnDefend, and BlueHammer, has released two new GitHub repositories containing exploitation tools. YellowKey targets BitLocker encryption bypass, while GreenPlasma exploits a Windows CTFMON vulnerability to achieve arbitrary privilege escalation. The public release of these tools increases their availability to other attackers and poses immediate risk to Windows systems.
Indicators of Compromise
- malware — YellowKey
- malware — GreenPlasma
- malware — RedSun
- malware — UnDefend
- malware — BlueHammer