Threat intelligence
- Suspected origin
- Colombia
- First seen
- 2018-01-01 00:00:00
- Motivation
- Information theft and espionage, Financial crime
- Targeted sectors
- Education, Energy, Financial, Government, Healthcare, Manufacturing, Transportation
- TLP
- WHITE
(Qihoo 360) Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government institutions as well as important corporations in financial sector, petroleum industry, professional manufacturing, etc.
Till this moment, 360 Threat Intelligence Center captured 29 bait documents, 62 Trojan samples and multiple related malicious domains in total. Attackers are targeting Windows platform and aiming at government institutions as well as big companies in Colombia.
Also known as
AguilaCiegaAPT-C-36APT-Q-98Blind EagleG0099TAG-144
Tooling and malware
CaminhoHeartCryptnjRATPureCrypterAsyncRATDCRATImminent MonitorQuasarRATRemcos
MITRE ATT&CK techniques
T1105 Ingress Tool TransferT1568 Dynamic ResolutionT1571 Non-Standard PortT1047 Windows Management InstrumentationT1534 Internal SpearphishingT1133 External Remote ServicesT1593 Search Open Websites/DomainsT1027 Obfuscated Files or InformationT1480 Execution Guardrails
Coverage 1
threat-intel
BraZetsu is a sophisticated, AI-enhanced Python malware framework developed by the threat actor known as Exilware, used to establish initial access for an underground marketplace called the Infected Marketplace. This mar…
