Blind Eagle, also known as APT-C-36, has targeted Latin American organizations since 2018, particularly Colombian government institutions, financial organizations and critical infrastructure. A campaign reported as ongoing since November 2024 used phishing links and malicious files requiring minimal user interaction to retrieve malware through WebDAV. Unlike attacks exploiting CVE-2024-43451 to harvest NTLMv2 hashes, the reported activity used this delivery mechanism to download malware.
In late February 2025, Darktrace observed a compromise at a Colombian customer and attributed it to Blind Eagle with medium confidence. Within five hours, the affected device downloaded executables, contacted suspicious infrastructure and uploaded 60 MiB and 5.6 MiB to two external endpoints; the reported evidence does not establish what those uploads contained. Automated containment was not enabled, and the compromise continued until the customer's security team responded to alerts. Defenders should prioritize monitoring unusual WebDAV downloads, subsequent executable activity and outbound uploads, and assess whether automated containment can shorten response times.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
The observed attack progressed from suspicious redirection and executable downloads to data exfiltration within approximately five hours. Darktrace recorded uploads of 60 MiB to 21ene.ip-ddns[.]com and 5.6 MiB to diciembrenotasenclub[.]longmusic[.]com, followed by continued beaconing.
In late February 2025, Darktrace observed a compromise in a Colombian customer's network and attributed it to Blind Eagle with medium confidence. The affected device downloaded an executable from 62[.]60[.]226[.]112 and subsequently contacted suspicious infrastructure, including 21ene.ip-ddns[.]com.
Microsoft patched the Windows vulnerability that could disclose NTLMv2 password hashes following minimal interaction with a malicious file. The described Blind Eagle campaign retained a minimal-interaction delivery mechanism after the patch, using it to deliver malware rather than harvest hashes.
A campaign targeting Colombian organizations began in November 2024. Phishing links delivered malicious files that triggered WebDAV requests and retrieved malware following minimal user interaction.
Blind Eagle, also known as APT-C-36, has been observed conducting cyberattacks across Latin America since 2018, particularly targeting Colombian government institutions, financial organizations, and critical infrastructure.
Darktrace generated alerts and correlated suspicious downloads, command-and-control connections, and external data transfers into a broader incident. Autonomous response was not enabled, so the compromise continued until the customer's security team responded.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.