CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 711

As cited

Copy frozen at (site build).

threat intel

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

Huntress detected active use of Nightmare-Eclipse attack tools (BlueHammer, RedSun, and UnDefend) during a real-world intrusion that began with a compromised FortiGate VPN, followed by reconnaissance and likely data tunneling activity. The incident demonstrates operational deployment of this toolset against production environments.

Why it matters: Security teams managing FortiGate VPN deployments and endpoint defenses need to hunt for signs of Nightmare-Eclipse tooling and the initial FortiGate compromise vectors, as this intrusion shows the toolset is actively weaponized in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

Huntress detected active deployment of Nightmare-Eclipse tools (BlueHammer, RedSun, UnDefend) during a real-world intrusion campaign. The attack chain began with FortiGate virtual private network (VPN) compromise, followed by reconnaissance commands and probable command-and-control tunneling.

Why it matters: Organizations running FortiGate VPNs face immediate risk from this exploit chain; security teams should hunt for these tool signatures and review FortiGate access logs for suspicious activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

Huntress detected active deployment of Nightmare-Eclipse tools (BlueHammer, RedSun, UnDefend) during a real-world intrusion campaign. The attack chain began with FortiGate virtual private network (VPN) compromise, followed by reconnaissance commands and probable command-and-control tunneling.

Why it matters: Organizations running FortiGate VPNs face immediate risk from this exploit chain; security teams should hunt for these tool signatures and review FortiGate access logs for suspicious activity.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary