← threatfilter.dev / all groups / APT-C-36
APT-C-36
Also known as: Blind Eagle · TAG-144 · AguilaCiega · APT-Q-98
Overview
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.
Targets
Finance · Government · Manufacturing · Petroleum · Private sector
Regions
Chile · Colombia · Ecuador · Panama · Spain
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 38 techniques across 8 tactics
Reconnaissance
Resource Development
-
T1583.001Domains -
T1583.003Virtual Private Server -
T1583.006Web Services -
T1584.005Botnet -
T1586.002Email Accounts -
T1586.003Cloud Accounts -
T1587.001Malware -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware -
T1683.001Written Content -
T1683.002Audio-Visual Content
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1133External Remote Services
Stealth
-
T1027Obfuscated Files or Information -
T1027.003Steganography -
T1027.013Encrypted/Encoded File -
T1027.016Junk Code Insertion -
T1036.004Masquerade Task or Service -
T1036.005Match Legitimate Resource Name or Location -
T1055.012Process Hollowing -
T1480Execution Guardrails -
T1564.003Hidden Window -
T1574.001DLL -
T1684.001Impersonation
Lateral Movement
-
T1534Internal Spearphishing
Command and Control
-
T1105Ingress Tool Transfer -
T1568Dynamic Resolution -
T1571Non-Standard Port
Tools & malware (9)
njRAT · Imminent Monitor · DCRAT · PureCrypter · Caminho · Remcos · AsyncRAT · QuasarRAT · HeartCrypt
Reporting (3)
- TAG-144’s Persistent Grip on South American Organizations — Insikt Group
- Blind Eagle: …And Justice for All — Check Point Research
- BlindEagle flying high in Latin America — Global Research & Analysis Team, Kaspersky