NEW: Group Profiler — instant APT intel lookup. Try it →

APT-C-36

G0099 Espionage MITRE ATT&CK →

Also known as: Blind Eagle · TAG-144 · AguilaCiega · APT-Q-98

Overview

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.

Naming & attribution

APT-C-36 is tracked under 5 names across the industry. It uses 38 documented ATT&CK techniques — more than 74% of the 174 groups tracked here. Activity attributed since at least 2018.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Blind EagleQiAnXin Threat Intelligence Center
TAG-144Insikt Group
AguilaCiegaInsikt Group
APT-Q-98Insikt Group

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1586.003 Cloud Accounts — used by 2 of 174 groups
  • T1683.001 Written Content — used by 2 of 174 groups
  • T1683.002 Audio-Visual Content — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA2541 — 18 shared techniques (38% overlap)
  • WIRTE — 15 shared techniques (31% overlap)
  • Earth Lusca China — 17 shared techniques (26% overlap)
  • LazyScripter — 12 shared techniques (26% overlap)
  • Gamaredon Group Russia — 21 shared techniques (24% overlap)
  • FIN7 — 20 shared techniques (24% overlap)

Malware families with current indicators

4 families attributed to APT-C-36, carrying 3,226 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Remcos 2,964 indicators
  • PureCrypter 259 indicators
  • AsyncRat 2 indicators
  • DcRat 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Finance · Government · Manufacturing · Petroleum · Private sector

Regions

Chile · Colombia · Ecuador · Panama · Spain

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 38 techniques across 8 tactics

Reconnaissance

Resource Development

Initial Access

Execution

Persistence

Lateral Movement

Command and Control

Tools & malware (9)

njRAT · Imminent Monitor · DCRAT · PureCrypter · Caminho · Remcos · AsyncRAT · QuasarRAT · HeartCrypt

Reporting (3)