Blind Eagle, also known as APT-C-36, APT-Q-98, AguilaCiega, and TAG-144, is a Spanish-speaking threat actor active since at least 2018. Its operations primarily target Colombian organizations, with additional targeting in Ecuador, Panama, Spain, and Chile. Victims include government agencies, financial institutions, healthcare organizations, telecommunications providers, and energy companies, including oil and gas organizations. The group relies heavily on phishing and spearphishing to distribute commodity remote-access trojans. Its lures impersonate tax authorities, courts, notaries, and traffic authorities, frequently using legal notifications, tax arrears, or personal-interest themes. Delivery mechanisms include malicious Office documents, embedded objects, scripts, and password-protected archives. Some campaigns use geographically filtered shortened links that redirect users outside the intended target geography, including users of major VPN services, to legitimate websites. Its malware repertoire includes modified Imminent Monitor and ProyectoRAT variants, njRAT, AsyncRAT, LimeRAT, Remcos, Warzone RAT, and BitRAT. Blind Eagle uses multistage VBScript and PowerShell chains to retrieve and execute payloads, including in-memory .NET loading and process hollowing into legitimate Windows processes. Persistence mechanisms include Startup-folder shortcuts and scheduled tasks, sometimes disguised as legitimate Google tasks. Defense-evasion techniques include hidden PowerShell execution, ConfuserEx obfuscation, compressed or encrypted payloads, and password-protected attachments. The group also uses HeartCrypt and PureCrypter and stages malware through legitimate cloud-storage and file-hosting services. Its remote-access malware supports continued access to compromised systems and information theft, while frequent changes to delivery methods and payloads complicate detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Threat actors have previously been observed exploiting CVE-2024-43451, a vulnerability in Microsoft Windows that allows the disclosure of a user’s NTLMv2 password hash upon minimal interaction with a malicious file. Microsoft patched the vulnerability in November 2024.
A recently patched security flaw affecting Windows NTLM has been exploited by malicious actors to leak NTLM hashes or user passwords and infiltrate systems since March 19, 2025. The flaw, CVE-2025-24054 (CVSS score: 6.5), is a hash disclosure spoofing bug that was fixed by Microsoft last month as part of its Patch Tuesday updates. The security flaw is assessed to be a variant of CVE-2024-43451 (CVSS score: 6.5), which was patched by Microsoft in November 2024 and has also been weaponized in the wild in attacks targeting Ukraine and Colombia by threat actors like UAC-0194 and Blind Eagle.
718 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a remote-access-trojan distribution campaign targeting Colombian public entities.
A Spanish-speaking group targeting Latin American government, financial, and corporate organizations. Analysis of a compromised apparent attacker workstation exposed RAT-building tools, phishing templates, bulk-email software, infrastructure records, and efforts to evade security detection.
Suspected Blind Eagle operators conducted phishing campaigns impersonating Colombian judicial bodies and traffic authorities. The operation delivered remote-access malware through password-protected archives and multi-stage loaders hosted across code repositories, cloud storage, and other legitimate services.
Referenced only for comparison with the infostealer category and prior infrastructure patterns; the article does not attribute the described GitHub-loader and phishing operation to Blind Eagle.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.