Blind Eagle, also tracked as APT-C-36, APT-Q-98, TAG-144, and AguilaCiega, is a Latin America-focused threat actor widely associated with sustained operations against Colombian targets and broader South American government entities. The group is best known for cyberespionage activity, though some reporting also links it to financially oriented operations, particularly banking-fraud-enabling malware use. Colombia is the most consistently reported focus of its campaigns, including repeated targeting of government institutions and judicial or ministerial entities. Blind Eagle commonly gains initial access through spearphishing, including password-protected attachments, malicious documents, shortcut files, and compromised internal email accounts used to bypass standard mail-authentication controls. The actor has repeatedly impersonated Colombian banks and government institutions in phishing lures. Delivery chains frequently rely on VBScript, PowerShell, HTA content, and multi-stage script loaders, often using layered obfuscation, encryption, steganographic elements, and open-directory staging servers. The group has also exploited CVE-2024-43451 in campaigns targeting Colombian entities. The actor regularly uses commodity and modified remote access trojans rather than bespoke implants. Malware associated with Blind Eagle includes Remcos RAT, AsyncRAT, Quasar RAT, njRAT, Lime-RAT, BitRAT, Agent Tesla, AveMariaRAT, DCRat, and a modified variant of Imminent Monitor. Recent reporting also describes a customized AsyncRAT build referred to internally as JC-46. That tooling demonstrates incremental tradecraft improvement while preserving familiar delivery and persistence patterns. Reported capabilities of this malware ecosystem include credential theft, keylogging, screenshot capture, webcam and audio capture, clipboard monitoring, reconnaissance, persistence through startup items and scheduled tasks, process hollowing and other injection methods, Windows Defender tampering, and hidden remote desktop or hidden VNC functionality used to facilitate banking fraud. Blind Eagle has shown repeated use of defense-evasion techniques, including ConfuserEx obfuscation, custom string and payload encoding schemes, AES and XOR-based protection, self-mutating scripts, process injection, parent-process spoofing, and legitimate interpreters or system binaries to stage execution. Multiple campaigns reused a distinctive scheduled-task-based persistence pattern disguised as legitimate software. Infrastructure patterns include exposed staging servers, dynamic DNS usage, VPS-backed operations, and movement of parts of its VBScript delivery infrastructure onto Russian bulletproof hosting. Overall, Blind Eagle is a persistent regional threat actor whose operations center on phishing-led compromise, commodity RAT deployment, stealthy script-based loaders, and long-running access to Colombian and other Latin American targets. Its activity is most strongly characterized as cyberespionage against government entities, with some overlap into financially motivated post-compromise abuse.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
A recently patched security flaw affecting Windows NTLM has been exploited by malicious actors to leak NTLM hashes or user passwords and infiltrate systems since March 19, 2025. The flaw, CVE-2025-24054 (CVSS score: 6.5), is a hash disclosure spoofing bug that was fixed by Microsoft last month as part of its Patch Tuesday updates. The security flaw is assessed to be a variant of CVE-2024-43451 (CVSS score: 6.5), which was patched by Microsoft in November 2024 and has also been weaponized in the wild in attacks targeting Ukraine and Colombia by threat actors like UAC-0194 and Blind Eagle.
586 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The alert concerns Remcos RAT activity linked to APT-C-36.
Banking-fraud-focused threat actor targeting Colombian and broader Latin American victims using Spanish-language phishing, VBScript-to-PowerShell loader chains, commodity RATs, custom obfuscation, process injection, HVNC, browser profile cloning, and persistence disguised as 'Photo Studio'.
Targeted government entities in South America, especially Colombia, using spearphishing and RATs in campaigns combining espionage and financial motives.
Conducts phishing/social engineering by impersonating Colombian banks and government institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.