- Home
- APT groups
- APT-C-36
APT group profile
APT-C-36
Group that MITRE describes as a suspected South American actor, active since at least 2018, combining espionage and financial fraud against government, banking, energy and other sectors in Colombia, Ecuador and the rest of Latin America.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
APT-C-36, also known as Blind Eagle, BlindEagle or TAG-144, is the persistent threat actor with the strongest documented focus on Latin America and, in particular, Colombia. MITRE ATT&CK describes it as a suspected South American group that, since at least 2018, has conducted espionage and financially motivated operations against government institutions and companies in the financial, energy and manufacturing sectors of Colombia and other countries in the region.
Its motivation is mixed. Kaspersky notes that the group alternates between purely financial attacks and espionage operations. Recorded Future considers its overall motivation to remain ambiguous and its activity to reflect both aims. No public source attributes it to a state. Check Point observed operating patterns in UTC-5, consistent with a South American origin.
Its hallmark is Spanish-language social engineering that impersonates Colombian entities, especially judicial authorities, other public institutions and local banks. It combines commercial or open-source RATs (AsyncRAT, njRAT, Remcos, QuasarRAT, DCRAT) with obfuscated loader chains, legitimate services to host payloads, and dynamic DNS as C2 infrastructure.
Notable campaigns
- 2018–2019: first public report, which documented ongoing attacks against Colombian government institutions and large companies since April 2018 (QiAnXin).
- 2023 (published in January): campaign against organizations in Ecuador with a more elaborate chain (password-protected LHA archives, mshta, PowerShell and Python) that delivered a banking-oriented QuasarRAT variant, along with geographic filtering of victims (Check Point).
- 2024: campaigns against Colombia, Ecuador, Chile and Panama that impersonated public entities and used steganography, DLL sideloading with HijackLoader and, from May onward, artifacts with Portuguese-language strings and Brazilian hosting (Kaspersky).
- November 2024 – February 2025:
.urlfiles that reproduce the behavior of CVE-2024-43451, adopted six days after Microsoft’s patch. The campaigns targeted Colombian judicial and government institutions, and one of them (December 19, 2024) affected more than 1,600 victims (Check Point). Darktrace detected an intrusion of this type at a Colombian customer in February 2025 (Darktrace). - 2025: LevelBlue linked, with high confidence, part of the VBScript delivery infrastructure to the bulletproof hosting provider Proton66 (LevelBlue). Recorded Future identified five activity clusters between 2024 and 2025, using compromised email accounts of Colombian entities (Recorded Future).
- September 2025: email sent from a likely compromised account to an entity attached to the Ministry of Commerce, Industry and Tourism, with an SVG judicial lure, a fileless chain, Caminho hosted on Discord and DCRAT injected into MSBuild.exe. Zscaler attributes the campaign with medium confidence (Zscaler).
- May–July 2026: new staging servers with an AsyncRAT version (JC-46) that adds injection via Windows Notification Facility, an HVNC banking fraud module with browser profile cloning, and evasion of Chrome’s App-Bound encryption (LevelBlue).
Key TTPs
Resource development. Hosts payloads on legitimate services (Google Drive, Dropbox, Bitbucket, GitHub, Discord, Pastebin) (T1583.006). Uses compromised email accounts (T1586.002) and obtains commercial malware and crypters such as Remcos, HeartCrypt and PureCrypter (T1588.001).
Initial access. Spearphishing with attachments (PDF, DOCX, protected RAR) (T1566.001) and with links, often through URL shorteners (T1566.002). Impersonates government entities and banks (T1684.001). Also sends internal emails from already compromised mailboxes (T1534).
Execution. Relies on the user opening the link or file (T1204.001, T1204.002) and chains VBScript, JavaScript and PowerShell (T1059.005, T1059.007, T1059.001), in some cases via WMI (T1047).
Persistence and evasion. Creates scheduled tasks that masquerade as Google utilities (T1053.005, T1036.004). Hides encoded or encrypted payloads inside images (T1027.003, T1027.013), uses process hollowing (T1055.012) and DLL sideloading (T1574.001), and applies geographic filtering so that only IPs from Colombia or Ecuador receive the payload (T1480).
Command and control. Uses dynamic DNS (DuckDNS, No-IP and others) (T1568) and non-standard ports (T1571), and downloads additional modules (T1105). The end goal is usually theft of banking credentials and remote control of the machine.
Detection and mitigation
- Email: look for Spanish-language lures with judicial or tax themes, SVG attachments,
.urlfiles, password-protected RAR or LHA archives, and shortened links. Emails arriving from legitimate accounts of Colombian public entities also warrant review. Apply attachment filtering and sandboxing (M1049, M1021) and train users on this type of lure (M1017). - Endpoint (EDR/Sysmon): hunt for
wscript.exe,mshta.exeorpowershell.exelaunched by email clients, browsers or Explorer. Watch for scheduled tasks with names that mimic Google products or “Photo Studio” (pivot suggested by LevelBlue) and legitimate .NET processes such asMSBuild.exemaking outbound connections (a process hollowing target according to Zscaler). Enable AMSI and PowerShell logging (Script Block Logging, ID 4104), and block or restrict VBScript and mshta where they are not used (M1042, M1038, M1040). - Network/DNS: alert on resolutions to dynamic DNS providers, script-initiated downloads from Discord CDN, Pastebin, GitHub or Bitbucket, outbound WebDAV traffic, and uncommon ports (M1031, M1037).
- Patching and configuration: keep Windows updates current (CVE-2024-43451) (M1051). Consider blocking the opening of
.urland.lnkfiles received by email. - Fraud: in banking, correlate endpoint telemetry with signals of remote or HVNC sessions and browser profile cloning. Require phishing-resistant MFA on corporate and banking portals (M1032).
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Resource Development
Execution
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1204.001 User Execution: Malicious Link
- T1204.002 User Execution: Malicious File
- T1574.001 Hijack Execution Flow: DLL
Privilege Escalation
- T1055.012 Process Injection: Process Hollowing
Stealth
Lateral Movement
- T1534 Internal Spearphishing
Malware and tools
Malware
References
Public sources this profile is based on.
- [1] APT-C-36, Group G0099 · MITRE ATT&CK, Jul 2026
- [2] APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations (archivo) · QiAnXin Threat Intelligence Center, Feb 2019
- [3] BlindEagle Targeting Ecuador With Sharpened Tools · Check Point Research, Jan 2023
- [4] BlindEagle flying high in Latin America · Kaspersky GReAT, Aug 2024
- [5] Blind Eagle: …And Justice for All · Check Point Research, Mar 2025
- [6] Patch and Persist: Darktrace's Detection of Blind Eagle (APT-C-36) · Darktrace, Jun 2025
- [7] Tracing Blind Eagle to Proton66 · LevelBlue SpiderLabs, Jun 2025
- [8] TAG-144's Persistent Grip on South American Organizations · Recorded Future Insikt Group, Aug 2025
- [9] BlindEagle Targets Colombian Government Agency with Caminho and DCRAT · Zscaler ThreatLabz, Dec 2025
- [10] Still Circling: Blind Eagle's Toolkit Keeps Evolving · LevelBlue SpiderLabs, Jul 2026
Profile last updated: