Blind Eagle, also tracked as APT-C-36, APT-Q-98, TAG-144, and AguilaCiega, is a Latin America-focused threat actor primarily associated with sustained cyberespionage activity against Colombian organizations, especially government, judicial, tax, foreign affairs, and other public-sector entities. The group has also impersonated Colombian banks and government institutions in phishing operations, and reporting has repeatedly characterized its operations as combining espionage objectives with financially motivated activity, particularly banking fraud. Blind Eagle is best known for spearphishing-driven intrusion chains that rely heavily on social engineering, malicious attachments, password-protected archives, malicious documents, shortcut files, VBScript, PowerShell, and scheduled-task persistence. The actor has repeatedly used compromised or internal email accounts to improve delivery success and bypass common email authentication controls. Campaigns have targeted victims across South America, but Colombia remains the most consistently observed focus. The group frequently uses commodity and modified remote access trojans rather than bespoke malware families. Malware associated with Blind Eagle activity has included AsyncRAT, Quasar RAT, njRAT, Remcos RAT, Agent Tesla, LimeRAT, BitRAT, AveMariaRAT, DCRat, and a modified variant of Imminent Monitor. Recent reporting also describes a customized AsyncRAT-derived toolset internally referred to as JC-46, reflecting incremental capability development rather than a wholesale shift away from the group’s established tooling patterns. Blind Eagle’s delivery chains commonly feature layered obfuscation and multi-stage script execution. Observed tradecraft includes VBScript-to-PowerShell loaders, JavaScript stages, AutoIt-based loaders, steganographic or encoded payload retrieval, inline C# compilation, process hollowing, and other in-memory execution methods. The actor has shown repeated use of custom string and payload obfuscation schemes, including XOR- and AES-based protection, self-mutating scripts, and bespoke decoding routines. Persistence has often been established through startup-folder artifacts and scheduled tasks disguised as legitimate software, with recurring reuse of the same persistence themes across otherwise distinct loader families, suggesting shared internal builders or templates. Operationally, Blind Eagle has demonstrated consistent reuse of exposed staging infrastructure, open directories, dynamic DNS patterns, VPS-backed infrastructure, and delivery servers hosting script-based malware components. Reporting has also linked portions of its delivery infrastructure to bulletproof hosting. The actor’s infrastructure and malware development practices indicate iterative refinement: retaining familiar phishing and script-loader tradecraft while selectively improving payloads most relevant to credential theft, remote control, and banking fraud. More advanced Blind Eagle payloads have been observed incorporating process injection techniques designed to reduce detection, including process hollowing and Windows Notification Facility-based injection. Customized payloads attributed to the group have also included capabilities such as keylogging, screenshot capture, webcam and audio capture, clipboard monitoring, credential theft, browser profile cloning, hidden remote desktop or hidden VNC functionality, reconnaissance, security-product awareness, and tampering with defensive controls. Some of these capabilities align with espionage collection, while others support account takeover and financial fraud. Blind Eagle is widely regarded as one of the most active and persistent threat actors operating against Colombian institutions. Its hallmark characteristics are high-volume phishing, rapid adoption of newly useful delivery techniques, extensive use of commodity RAT ecosystems, and steady evolutionary improvement of loaders and post-compromise tooling while maintaining a strong regional focus on Latin American targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
A recently patched security flaw affecting Windows NTLM has been exploited by malicious actors to leak NTLM hashes or user passwords and infiltrate systems since March 19, 2025. The flaw, CVE-2025-24054 (CVSS score: 6.5), is a hash disclosure spoofing bug that was fixed by Microsoft last month as part of its Patch Tuesday updates. The security flaw is assessed to be a variant of CVE-2024-43451 (CVSS score: 6.5), which was patched by Microsoft in November 2024 and has also been weaponized in the wild in attacks targeting Ukraine and Colombia by threat actors like UAC-0194 and Blind Eagle.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking-fraud-focused threat actor targeting Colombian and broader Latin American victims using Spanish-language phishing, VBScript-to-PowerShell loader chains, commodity RATs, custom obfuscation, process injection, HVNC, browser profile cloning, and persistence disguised as 'Photo Studio'.
Targeted government entities in South America, especially Colombia, using spearphishing and RATs in campaigns combining espionage and financial motives.
Conducts phishing/social engineering by impersonating Colombian banks and government institutions.
Threat actor targeting Colombian government/judicial and other institutions using NTLM-related abuse and RAT delivery, including GitHub-based attack elements.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.