Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

BlueHammer turns into a ransomware step

2 min read
16:08UTC

CISA confirmed ransomware gangs are weaponising BlueHammer, the April Windows Defender flaw, to seize SYSTEM rights before deploying their encryptors.

TechnologyDeveloping
Key takeaway

A patched April flaw in Windows Defender is now a live SYSTEM-access step for ransomware crews.

CISA updated the Known Exploited Vulnerabilities (KEV) entry for CVE-2026-33825, the Windows Defender local-privilege-escalation (LPE) flaw known as BlueHammer, to confirm that ransomware gangs now exploit it for SYSTEM-level access before deploying encryptors. Microsoft patched the flaw on 14 April and CISA listed it on 22 April. It was disclosed by a researcher using the handle Chaotic Eclipse, whose run of Microsoft bugs produced a fifth unpatched zero-day last month . 1

The flaw works as a time-of-check-to-time-of-use race in Defender's remediation engine: the software checks a file's status, then acts on it a moment later, and an attacker swaps the target in between. On its own an LPE does nothing. Chained after an initial break-in, it hands an attacker the SYSTEM rights needed to switch off defences and encrypt at will. That is why the update matters: it turns a three-month-old patch that many programmes deprioritised into a live step in a working ransomware chain.

Deep Analysis

In plain English

Windows Defender is the built-in security software that comes free with Windows and is meant to stop malware. Researchers found a flaw in it that lets someone who has already broken into a computer, through some other route, use Defender itself to take full control of the machine, the highest level of access there is. CISA now says ransomware gangs are using this trick before locking victims' files, which is unsettling because the tool that is supposed to protect the computer has become part of the attack. A researcher who goes by the handle Chaotic Eclipse found the flaw; that same person has found several other serious Windows bugs this year.

Deep Analysis
Root Causes

Windows Defender's kernel-mode components run with system-level trust by design, which is precisely why compromising the security product itself hands a ransomware crew system-level access that a bug in an ordinary, already-restricted application cannot.

Chaotic Eclipse, the same handle already credited with a fifth zero-day disclosure this year, appears to work through private broker or bug-bounty channels rather than Microsoft's own coordinated-disclosure programme. The gap between a privately attributed find and CISA's public 'now confirmed exploited' update suggests BlueHammer circulated in criminal channels before any public patch timeline closed it.

What could happen next?
  • Risk

    Organisations that rely on Windows Defender as their primary endpoint protection now face a scenario where the protection layer itself can be turned against them at the privilege-escalation stage of an intrusion.

  • Meaning

    CISA's decision to update rather than newly list the entry signals the flaw was already tracked before ransomware use was confirmed, suggesting future KEV updates on existing entries deserve the same attention as new listings.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BleepingComputer· 4 Jul 2026
Read original
Causes and effects
This Event
BlueHammer turns into a ransomware step
A patch many teams deprioritised in April has become a confirmed rung in the ransomware kill chain.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.