news.mlab.sh
Threat intelligence
Threat actor

Blind Eagle

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Colombia
First seen
2018-01-01 00:00:00
Motivation
Information theft and espionage, Financial crime
Targeted sectors
Education, Energy, Financial, Government, Healthcare, Manufacturing, Transportation
TLP
WHITE

(Qihoo 360) Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government institutions as well as important corporations in financial sector, petroleum industry, professional manufacturing, etc. Till this moment, 360 Threat Intelligence Center captured 29 bait documents, 62 Trojan samples and multiple related malicious domains in total. Attackers are targeting Windows platform and aiming at government institutions as well as big companies in Colombia.

Also known as

AguilaCiegaAPT-C-36APT-Q-98Blind EagleG0099TAG-144

Tooling and malware

CaminhoHeartCryptnjRATPureCrypterAsyncRATDCRATImminent MonitorQuasarRATRemcos

MITRE ATT&CK techniques

T1105 Ingress Tool TransferT1568 Dynamic ResolutionT1571 Non-Standard PortT1047 Windows Management InstrumentationT1534 Internal SpearphishingT1133 External Remote ServicesT1593 Search Open Websites/DomainsT1027 Obfuscated Files or InformationT1480 Execution Guardrails

Coverage 1