TAG-144
TAG-144, also known as Blind Eagle, AguilaCiega, APT-C-36, and APT-Q-98, is a threat actor tracked by Recorded Future's Insikt Group and active since at least 2018. Insikt Group identified five distinct activity clusters linked to the group operating during 2024 and 2025. The actor primarily targets South America, especially Colombia, with victims concentrated in Colombian government entities at the local, municipal, and federal levels. Reported targets also include judiciary and tax authorities, financial entities, petroleum and energy companies, and organizations in education, healthcare, manufacturing, and professional services. Additional activity has been observed in Ecuador, Chile, and Panama, with occasional campaigns in North America targeting Spanish-speaking users. The group's motivation is described as ambiguous, reflecting both cyber-espionage and financially driven objectives. Its campaigns have been associated with credential theft, including banking-related keylogging and browser monitoring, as well as surveillance-oriented activity against government institutions. Reported outcomes include credential theft, data exfiltration, and extortion. TAG-144 commonly gains initial access through spearphishing, often impersonating local government agencies and using lures themed around debt collection and judicial notifications. The group has used compromised Colombian government email accounts in spearphishing campaigns. It uses URL shorteners such as cort[.]as, acortaurl[.]com, and gtly[.]to to conceal malicious links and target users geographically, and employs geo-fencing to block access from outside Colombia or Ecuador, sometimes redirecting non-targets to official government websites. Its tooling relies heavily on commodity, open-source, cracked, and modified remote access trojans, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, LimeRAT, njRAT, QuasarRAT, BitRAT, and a Quasar variant called BlotchyQuasar. The actor also uses crypters including HeartCrypt, PureCrypter, and crypters developed by actors known as Roda and pjoao1578, with indicators also pointing to use of crypter-as-a-service offerings such as CryptersAndTools. TAG-144 uses multi-stage infection chains and legitimate internet services for payload staging, along with dynamic DNS providers. Its evasion and delivery techniques include steganography to embed payloads in image files, domain generation algorithms, and in-memory malware execution. Command-and-control infrastructure has incorporated IP space from Colombian ISPs and VPS providers and dynamic DNS services such as duckdns[.]org, ip-ddns[.]com, and noip[.]com. Insikt Group also reported further evidence linking TAG-144 to Red Akodon. The five identified clusters share similar TTPs but differ significantly in infrastructure, malware deployment, and other operational methods.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- government
- finance
- energy
- education
- healthcare
- manufacturing
Associated malware families
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TAG-144 is a cyberespionage group targeting South American government agencies, especially in Colombia, using commodity RATs, spear-phishing, and advanced evasion techniques.
TAG-144 is a cyberespionage group targeting South American government agencies, especially in Colombia, using commodity RATs, spear-phishing, and advanced evasion techniques.
Regionally focused intrusion activity (blending espionage and financially motivated credential theft) primarily targeting Colombian government entities via spearphishing, multi-stage loaders, and commodity/cracked RATs; heavy use of dynamic DNS and legitimate internet services for payload staging and C2 obfuscation.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.