Saltar al contenido

Perfil de grupo APT

APT-C-36

Grupo que MITRE describe como presunto actor sudamericano, activo desde al menos 2018, que combina espionaje y fraude financiero contra gobierno, banca, energía y otros sectores en Colombia, Ecuador y el resto de Latinoamérica.

MITRE G0099 EspionajeFinanciera LATAM · Colombia Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Desarrollo de recursos

Acceso inicial

Ejecución

  • T1047 Windows Management Instrumentation
  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic
  • T1059.007 Command and Scripting Interpreter: JavaScript
  • T1204.001 User Execution: Malicious Link
  • T1204.002 User Execution: Malicious File
  • T1574.001 Hijack Execution Flow: DLL

Escalamiento de privilegios

  • T1055.012 Process Injection: Process Hollowing

Sigilo

  • T1027.003 Obfuscated Files or Information: Steganography
  • T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
  • T1036.004 Masquerading: Masquerade Task or Service
  • T1480 Execution Guardrails
  • T1684.001 Social Engineering: Impersonation

Movimiento lateral

  • T1534 Internal Spearphishing

Comando y control

  • T1105 Ingress Tool Transfer
  • T1568 Dynamic Resolution
  • T1571 Non-Standard Port

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] APT-C-36, Group G0099 · MITRE ATT&CK, jul. 2026
  2. [2] APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations (archivo) · 360 Threat Intelligence Center, feb. 2019
  3. [3] BlindEagle Targeting Ecuador With Sharpened Tools · Check Point Research, ene. 2023
  4. [4] BlindEagle flying high in Latin America · Kaspersky GReAT, ago. 2024
  5. [5] Blind Eagle: …And Justice for All · Check Point Research, mar. 2025
  6. [6] Patch and Persist: Darktrace's Detection of Blind Eagle (APT-C-36) · Darktrace, jun. 2025
  7. [7] Tracing Blind Eagle to Proton66 · LevelBlue SpiderLabs, jun. 2025
  8. [8] TAG-144's Persistent Grip on South American Organizations · Recorded Future Insikt Group, ago. 2025
  9. [9] BlindEagle Targets Colombian Government Agency with Caminho and DCRAT · Zscaler ThreatLabz, dic. 2025
  10. [10] Still Circling: Blind Eagle's Toolkit Keeps Evolving · LevelBlue SpiderLabs, jul. 2026

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.