APT-C-36, also known as Blind Eagle, continued spear-phishing campaigns against Colombian and broader South American government, financial, healthcare, telecommunications, energy, and oil-and-gas organizations. The likely Colombia-based group used tax-authority, judicial, traffic-authority, and personal-infidelity lures to distribute password-protected PDF/DOCX-linked archives, with geographically filtered shortened URLs directing selected victims to hosted BitRAT and other remote-access malware. Researchers assess the activity is likely financially motivated rather than espionage-focused.
A LevelBlue investigation linked GitHub account cabeto850128, used to stage an AutoIt loader, to an email address exposed in ALIEN TXTBASE infostealer logs from a compromised device dubbed “Ghost.” Artifacts on that system included phishing templates, bulk-mail tools, RAT builds including AsyncRAT, DcRat, Remcos, and XWorm, and delivery infrastructure using GitHub, Bitbucket, AWS S3, actor-controlled domains, and DuckDNS. The reconstructed infection chain used self-extracting RAR archives, VBScript, concealed PowerShell, ProgramData-resident scripts, and InstallUtil.exe, with AsyncRAT-related traffic tied to dccomicrat81[.]duckdns.org; researchers cautioned that the evidence supports operational linkage but does not identify a real-world operator.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
The cabeto850128 account created the jacobo repository containing archivo.zip. Researchers later noted that the repository reused the archivo.zip filename with different content.
The cabeto850128 account resumed activity and created the comicsam repository, later identified as hosting components of an AutoIt-based malware loader.
The GitHub account cabeto850128 was created with a placeholder repository named test.
APT-C-36, also known as Blind Eagle, had targeted organizations in Colombia and other South American countries through spam and spear-phishing campaigns since at least 2019.
Analysis of matched samples found self-extracting RAR archives launching VBScript and obfuscated PowerShell, writing scripts to ProgramData, and abusing InstallUtil.exe. The reconstructed infrastructure used GitHub and alternate Bitbucket or AWS S3 staging, with AsyncRAT traffic associated with dccomicrat81[.]duckdns.org and per-build delivery paths on creainovada[.]xyz.
Researchers linked cabeto850128 GitHub commit metadata to an email address found in ALIEN TXTBASE stealer logs and associated with an infostealer-compromised device named Ghost. Recovered artifacts included RAT build folders, Colombian government-themed phishing templates, and bulk-email tooling, though the evidence did not establish an operator's identity.
APT-C-36 used DIAN tax and personal-infidelity lures with password-protected PDF or DOCX attachments and geofiltered shortened URLs to deliver BitRAT archives. The activity primarily targeted Colombian organizations, with additional targets in Ecuador, Spain, and Panama across government, financial, healthcare, telecommunications, energy, oil, and gas sectors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcelevelblue.com
Open sourcetrendaisecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.