Back
BigDiskBuster: NightmareEclipse's new PoC blocks Microsoft Defender updates
SiTech AI Team3 წთ. საკითხავი

BigDiskBuster: NightmareEclipse's new PoC blocks Microsoft Defender updates

Security researcher NightmareEclipse has published BigDiskBuster, a proof-of-concept that stops Microsoft Defender Antivirus from installing platform and security intelligence updates, leaving the antivirus running but stuck on its current version.

Security researcher NightmareEclipse has released a new proof-of-concept tool that stops Microsoft Defender Antivirus from updating itself. BigDiskBuster does not switch the antivirus off — it prevents Defender from installing platform and security intelligence updates, leaving the software running but stuck on its current version.

What BigDiskBuster does

The researcher, also known as Abdelhamid Naceri, published the code on GitHub and called it similar to their earlier UnDefend tool. "Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," NightmareEclipse wrote. They say it works on all supported Windows versions, though the current PoC is, by their own admission, "a bit buggy and needs some rewritting". The compatibility claim is unverified.

The mechanism is unusual: BigDiskBuster waits for a Defender update to begin, then creates hidden temporary files sized to consume the drive's free space, adding threads as needed to claim more. With no room left, the update fails; once the tool sees the failure, it closes the files and returns the space. It also opens Microsoft's Malicious Software Removal Tool, MRT.exe, restricting other processes' access while the handle stays open.

Old definitions, weaker defence

A screenshot published with the PoC shows Windows Security reporting a failed protection definition update with error 0x80070643 — a generic installation error that is not evidence on its own that BigDiskBuster is at work. The risk is clear: an antivirus that keeps running but stops receiving Microsoft's newest threat definitions may be less able to identify freshly detected malware.

Part of a long-running feud

The release continues a public dispute between the researcher and Microsoft. NightmareEclipse began dumping Windows zero-days in April, saying Microsoft had mistreated them and cut off access to its vulnerability reporting system. In May the company criticised the releases, saying the bugs had not come through official channels, and invoked its Digital Crimes Unit — widely read as a threat of legal action. Microsoft later said it had no intention of pursuing action against people doing or publishing security research, but by then the researcher's GitHub account and portal access were gone.

The dumps continued: RoguePlanet in June, LegacyHive in July, ShieldBreak in August and ShieldCrash in September. Some earlier zero-days were later patched, others exploited in the wild. BigDiskBuster is different: it offers no route to SYSTEM privileges, targeting a basic every antivirus needs — the ability to update itself. There is no indication the tool has been used in real-world attacks, and Microsoft has not responded to questions about it.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.