Skip to content

APT group profile

APT-C-36

Group that MITRE describes as a suspected South American actor, active since at least 2018, combining espionage and financial fraud against government, banking, energy and other sectors in Colombia, Ecuador and the rest of Latin America.

MITRE G0099 EspionageFinancial LATAM · Colombia Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Resource Development

Initial Access

Execution

  • T1047 Windows Management Instrumentation
  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic
  • T1059.007 Command and Scripting Interpreter: JavaScript
  • T1204.001 User Execution: Malicious Link
  • T1204.002 User Execution: Malicious File
  • T1574.001 Hijack Execution Flow: DLL

Privilege Escalation

  • T1055.012 Process Injection: Process Hollowing

Stealth

  • T1027.003 Obfuscated Files or Information: Steganography
  • T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
  • T1036.004 Masquerading: Masquerade Task or Service
  • T1480 Execution Guardrails
  • T1684.001 Social Engineering: Impersonation

Lateral Movement

  • T1534 Internal Spearphishing

Command and Control

  • T1105 Ingress Tool Transfer
  • T1568 Dynamic Resolution
  • T1571 Non-Standard Port

Malware and tools

References

Public sources this profile is based on.

  1. [1] APT-C-36, Group G0099 · MITRE ATT&CK, Jul 2026
  2. [2] APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations (archivo) · QiAnXin Threat Intelligence Center, Feb 2019
  3. [3] BlindEagle Targeting Ecuador With Sharpened Tools · Check Point Research, Jan 2023
  4. [4] BlindEagle flying high in Latin America · Kaspersky GReAT, Aug 2024
  5. [5] Blind Eagle: …And Justice for All · Check Point Research, Mar 2025
  6. [6] Patch and Persist: Darktrace's Detection of Blind Eagle (APT-C-36) · Darktrace, Jun 2025
  7. [7] Tracing Blind Eagle to Proton66 · LevelBlue SpiderLabs, Jun 2025
  8. [8] TAG-144's Persistent Grip on South American Organizations · Recorded Future Insikt Group, Aug 2025
  9. [9] BlindEagle Targets Colombian Government Agency with Caminho and DCRAT · Zscaler ThreatLabz, Dec 2025
  10. [10] Still Circling: Blind Eagle's Toolkit Keeps Evolving · LevelBlue SpiderLabs, Jul 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.