APT-C-36 (Blind Eagle) is a suspected South American threat actor known for spearphishing campaigns deploying diverse RATs against government, petroleum, and financial sectors.
Analyst brief
APT-C-36 (Blind Eagle) is a threat actor suspected to originate from South America. It primarily targets government institutions and corporations in the petroleum, manufacturing, and financial sectors across Colombia, Ecuador, Spain, Panama, and Chile. The group's key TTPs revolve around spearphishing (T1566.001, .002) with malicious attachments or links, delivering a diverse RAT toolkit including njRAT, Remcos, AsyncRAT, and PureCrypter, while using WMI (T1047) for execution and junk code (T1027.016) for evasion. Defenders should focus on email security gateways, monitoring for suspicious WMI and PowerShell activity, and blocking C2 infrastructure associated with known RAT families, especially those using Dynamic DNS (T1568).
APT-C-36
Blind EagleTAG-144AguilaCiega
unknown
Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government institutions as well as important corporations in financial sector, petroleum industry, professional manufacturing, etc.