
LegacyHive Abuses Windows Profile Loading to Hijack Administrator Registry Hives
The Nightmare-Eclipse disclosure actor has released LegacyHive, its latest Windows proof-of-concept, following prior drops including GreenPlasma, YellowKey, MiniPlasma, RoguePlanet, and GreatXML. Unlike traditional vulnerability disclosures, LegacyHive doesn’t exploit a memory corruption bug or logic flaw; instead, it abuses legitimate Windows profile initialization and registry hive loading mechanisms to hijack another user’s environment. LevelBlue’s OpsIntel CTI […]
The post LegacyHive Abuses Windows Profile Loading to Hijack Administrator Registry Hives appeared first on Cyber Security News.