Affected Systems
CrowdStrike Falcon Sensor (all current versions) on Windows 11 25H2 and Windows Server 2025. Vulnerability affects the Office malicious macros remediation feature. No CVE assigned yet.
Exploitation Status
Public PoC released by researcher "Nightmare Eclipse." Exploit confirmed working by independent security experts. CrowdStrike states detections now in place, but obfuscation may bypass. Active exploitation in the wild unknown.
Business Impact
Attackers with local access can escalate to SYSTEM privileges, bypassing endpoint protection. Organizations using CrowdStrike Falcon for endpoint security face elevated risk of lateral movement and persistence if attackers gain initial foothold. Workaround available but disables macro remediation feature, reducing protection against Office-based malware.
Urgency
đź”´ Immediate
Recommended Actions
- Disable the 'Microsoft Office File Suspicious Macro Removal' Windows policy setting in CrowdStrike Falcon immediately per vendor guidance
- Access CrowdStrike support portal for the FalconFlank Tech Alert and follow all remediation steps provided
- Monitor for suspicious SYSTEM-level process creation, especially command prompts spawned by CrowdStrike Falcon processes
- Review endpoint logs for unusual activity related to Office macro handling and CrowdStrike Falcon Sensor service interactions
- Implement compensating controls: restrict local admin rights, enforce application whitelisting, and increase monitoring of privilege escalation attempts until patch is available
---
# Threat Actor Context
Actor Profile
Nightmare Eclipse is a security researcher operating under an anonymous handle who has disclosed multiple zero-day vulnerabilities targeting major security and operating system vendors since April 2026. The actor's motivation appears to be public disclosure of security flaws, with a pattern of releasing proof-of-concept exploits for privilege escalation and denial-of-service vulnerabilities. Nightmare Eclipse has targeted Microsoft products (Defender, BitLocker, Windows components), endpoint security platforms (CrowdStrike Falcon, Kaspersky, Avast), and hardware vendors (Nvidia). Microsoft has previously issued warnings of potential legal action against the researcher, characterizing the activity as "malicious activity causing real harm to our customers," though Nightmare Eclipse continues disclosure operations.
TTPs (Tactics, Techniques, Procedures)
The actor employs vulnerability research and exploit development techniques to identify zero-day flaws in widely deployed security software. The FalconFlank exploit specifically abuses CrowdStrike Falcon's Office malicious macros remediation feature to achieve privilege escalation to SYSTEM level (likely mapping to T1068: Exploitation for Privilege Escalation). The researcher demonstrates OPSEC awareness by noting that obfuscation and alternative DLL loading techniques are required to evade detection after initial disclosure. The actor's broader campaign includes privilege escalation exploits (HardBreacher for Kaspersky, PrettyPrague for Avast) and denial-of-service capabilities (GreenSection for Nvidia), alongside multiple Windows component zero-days (LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend). The disclosure pattern suggests systematic vulnerability research across endpoint security products and operating system components.
Targets & Patterns
Nightmare Eclipse targets widely deployed enterprise security infrastructure and operating system components rather than specific organizations or sectors. The actor focuses on endpoint protection platforms (CrowdStrike Falcon, Kaspersky Antivirus for Endpoint, Avast Antivirus), Microsoft Windows security features (Defender, BitLocker), and system-level components across Windows 11 25H2 and Windows Server 2025. This targeting pattern suggests the actor seeks maximum impact through vulnerabilities affecting broad enterprise deployments. The focus on security products specifically creates a paradox where organizations relying on these tools for protection become vulnerable through the products themselves. The researcher's choice of targets—major vendors with extensive enterprise market share—maximizes the potential reach and impact of disclosed vulnerabilities. No evidence suggests targeting of specific geographic regions, industries, or individual organizations; rather, the actor appears focused on systemic vulnerabilities in widely trusted security infrastructure.
Historical Context
Nightmare Eclipse began public zero-day disclosure activity in April 2026 with Microsoft-focused exploits. The FalconFlank disclosure represents an expansion from Microsoft products to third-party endpoint security platforms, disclosed in September 2026 alongside zero-days for Kaspersky (HardBreacher), Avast (PrettyPrague), and Nvidia (GreenSection). Of the Microsoft zero-days disclosed earlier (LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend), Microsoft has patched LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, while BlueHammer, RedSun, and UnDefend remain unpatched. Microsoft's legal threat following initial disclosures did not deter continued activity. Cybersecurity expert Kevin Beaumont independently confirmed the validity of Nightmare Eclipse's September 2026 exploits, lending credibility to the researcher's technical capabilities. The escalation from single-vendor focus to multi-vendor disclosure in September 2026 suggests either expanded research capacity or coordinated release of previously discovered vulnerabilities.
Defensive Recommendations
- Immediately disable the Microsoft Office File Suspicious Macro Removal Windows policy setting in CrowdStrike Falcon as advised by vendor; rely on Cloud Anti-malware for Microsoft Office Files settings instead
- Monitor for unusual SYSTEM-level process creation, particularly command prompts (cmd.exe, powershell.exe) spawned by CrowdStrike Falcon service processes (T1068 privilege escalation indicators)
- Review CrowdStrike Falcon exclusion lists for unauthorized entries that could allow FalconFlank PoC execution without detection
- Implement application control policies to restrict DLL loading techniques and monitor for suspicious DLL loads associated with CrowdStrike Falcon processes
- Access the FalconFlank Tech Alert on CrowdStrike's support portal for vendor-specific indicators and detection signatures; apply any available patches or configuration updates immediately
- Given Nightmare Eclipse's multi-vendor targeting pattern, audit privilege escalation opportunities across all endpoint security products (Kaspersky, Avast) and apply vendor guidance for HardBreacher and PrettyPrague exploits if applicable
