Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets.
Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The LevelBlue report says Blind Eagle's JC-46 payload added WNF-based process injection, custom Base28 encoding, HVNC for banking fraud, browser profile cloning, and a Chrome App-Bound Encryption v20 bypass, indicating incremental upgrades focused on banking fraud.
LevelBlue researchers observed four notable Blind Eagle developments between late May and early July 2026: a third string-obfuscation scheme with a JavaScript AES stage, an AutoIt3 RunPE loader staged via raw.githubusercontent.com, reuse of the 'Photo Studio' persistence disguise, and an upgraded AsyncRAT build named JC-46.
The Recorded Future report cites additional evidence connecting TAG-144 to Red Akodon and notes the use of compromised Colombian government email accounts to support spearphishing operations.
Insikt Group reported identifying five distinct TAG-144 activity clusters operating across 2024 and 2025, mainly targeting Colombian government entities at local, municipal, and federal levels. The clusters shared tactics such as commodity RATs, dynamic DNS, and legitimate internet services for staging, while differing in infrastructure and malware deployment.
Recorded Future describes TAG-144, also known as Blind Eagle, as having been active since at least 2018, primarily targeting Colombia and broader South America.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.