Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

BlueHammer turns into a ransomware step

2 min read
18:20UTC

CISA confirmed ransomware gangs are weaponising BlueHammer, the April Windows Defender flaw, to seize SYSTEM rights before deploying their encryptors.

TechnologyDeveloping
Key takeaway

A patched April flaw in Windows Defender is now a live SYSTEM-access step for ransomware crews.

CISA updated the Known Exploited Vulnerabilities (KEV) entry for CVE-2026-33825, the Windows Defender local-privilege-escalation (LPE) flaw known as BlueHammer, to confirm that ransomware gangs now exploit it for SYSTEM-level access before deploying encryptors. Microsoft patched the flaw on 14 April and CISA listed it on 22 April. It was disclosed by a researcher using the handle Chaotic Eclipse, whose run of Microsoft bugs produced a fifth unpatched zero-day last month . 1

The flaw works as a time-of-check-to-time-of-use race in Defender's remediation engine: the software checks a file's status, then acts on it a moment later, and an attacker swaps the target in between. On its own an LPE does nothing. Chained after an initial break-in, it hands an attacker the SYSTEM rights needed to switch off defences and encrypt at will. That is why the update matters: it turns a three-month-old patch that many programmes deprioritised into a live step in a working ransomware chain.

Deep Analysis

In plain English

Windows Defender is the built-in security software that comes free with Windows and is meant to stop malware. Researchers found a flaw in it that lets someone who has already broken into a computer, through some other route, use Defender itself to take full control of the machine, the highest level of access there is. CISA now says ransomware gangs are using this trick before locking victims' files, which is unsettling because the tool that is supposed to protect the computer has become part of the attack. A researcher who goes by the handle Chaotic Eclipse found the flaw; that same person has found several other serious Windows bugs this year.

Deep Analysis
Root Causes

Windows Defender's kernel-mode components run with system-level trust by design, which is precisely why compromising the security product itself hands a ransomware crew system-level access that a bug in an ordinary, already-restricted application cannot.

Chaotic Eclipse, the same handle already credited with a fifth zero-day disclosure this year, appears to work through private broker or bug-bounty channels rather than Microsoft's own coordinated-disclosure programme. The gap between a privately attributed find and CISA's public 'now confirmed exploited' update suggests BlueHammer circulated in criminal channels before any public patch timeline closed it.

What could happen next?
  • Risk

    Organisations that rely on Windows Defender as their primary endpoint protection now face a scenario where the protection layer itself can be turned against them at the privilege-escalation stage of an intrusion.

  • Meaning

    CISA's decision to update rather than newly list the entry signals the flaw was already tracked before ransomware use was confirmed, suggesting future KEV updates on existing entries deserve the same attention as new listings.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BleepingComputer· 4 Jul 2026
Read original
Causes and effects
This Event
BlueHammer turns into a ransomware step
A patch many teams deprioritised in April has become a confirmed rung in the ransomware kill chain.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.