← All news

ransomware

BlueHammer Defender Flaw Now in the Ransomware Toolkit

2026-06-30

Remember BlueHammer? The Microsoft Defender privilege escalation flaw a researcher tossed onto the public internet back in April, fed up with how Microsoft handles disclosures? CISA confirmed on Monday that ransomware gangs are now running it in live attacks.

The bug, tracked as CVE-2026-33825, lets a local attacker reach into the Security Account Manager database, pull password hashes, and escalate to SYSTEM. As Tharros vulnerability analyst Will Dormann put it at the time, once an attacker is sitting at SYSTEM they basically own the machine. Microsoft shipped a patch on 14 April. Huntress Labs reported hands-on-keyboard exploitation within days of the fix going out.

The researcher behind the leak has been prolific

The person who dropped BlueHammer, who goes by Nightmare Eclipse, has not been idle since. Over the past few months they have burned a string of Windows zero-days with names that read like a paint catalogue: RoguePlanet, RedSun, GreenPlasma, MiniPlasma, YellowKey and UnDefend. The targets span Defender, BitLocker and other core Windows components. Microsoft patched three of them in the June Patch Tuesday round.

The motivation, as best anyone can tell from the leaker's own posts, is frustration. Reports that sit untouched for months, bug bounty payouts that arrive late or not at all, severity ratings that get quietly downgraded. None of that excuses dumping working exploits where ransomware crews can grab them, but it does explain how we got here.

From targeted use to commodity tool

CISA added BlueHammer to its Known Exploited Vulnerabilities catalogue in April and gave federal agencies two weeks to patch. Monday's update is more of a confirmation than a surprise. The flaw has now made the journey every leaked privilege escalation eventually makes: from targeted zero-day work into the off-the-shelf ransomware toolkit, where it will sit for years quietly picking off anyone slow to update.

That last part matters more than the headline. Initial access brokers and ransomware affiliates do not need novel exploits. They need reliable ones. A privilege escalation that drops password hashes out of the SAM and hands over SYSTEM, with a working exploit already circulating and plenty of unpatched targets, is exactly the kind of thing that earns a permanent slot in the playbook.

What this means for defenders

The fix has been out for months. The work is unglamorous:

  • Confirm the April Windows updates are applied across every endpoint, not just the ones that report in cleanly.
  • Pay attention to the stragglers. Laptops that never come back to the office, kiosks, the dusty machine in the corner of the warehouse. That is where these bugs live longest.
  • Watch for Defender tamper alerts and unexpected local privilege changes. Once an attacker has SYSTEM, they will start turning things off.

If your April updates are still pending on any Windows endpoint, that is the gap worth closing this week.

BlueHammer Defender Flaw Now in the Ransomware Toolkit | RiskSense