Blind Eagle, also tracked as APT-C-36, APT-Q-98, TAG-144, and AguilaCiega, is a Latin America-focused threat actor most consistently associated with operations against organizations in Colombia and the broader South American region. The group has been active for years and is known for sustained phishing-led intrusion activity using Spanish-language lures, rapid payload rotation, and heavy reliance on commodity malware and customized remote access trojans. Reporting has linked the actor to campaigns against government entities as well as organizations in finance, health care, telecommunications, and energy. Colombia is the most prominent target, with additional activity observed against entities in Ecuador, Panama, Spain, and Chile. Blind Eagle commonly gains initial access through spearphishing emails carrying malicious attachments or links, including password-protected archives and Office documents that require user interaction such as enabling macros. Delivery chains have included embedded VBScript in Word documents, VBScript-to-PowerShell loaders, staged downloads of additional payloads, and scheduled-task-based persistence disguised as legitimate software activity. The actor has also used hidden PowerShell execution, process hollowing, and DLL side-loading, including use of HijackLoader, to evade detection and execute payloads within legitimate processes. The group is notable for extensive use of commodity and open-source malware, including AsyncRAT, BitRAT, DCRat, LimeRAT, NjRAT, Quasar RAT, Remcos, PureCrypter, HeartCrypt, and related loaders and packers. More recent activity shows selective technical improvement rather than a wholesale shift in tradecraft. Observed 2026 operations included multiple obfuscated VBScript and JavaScript loader families, AutoIt-based RunPE delivery, repeated reuse of a "Photo Studio" persistence theme, and a customized AsyncRAT variant referred to as JC-46. That payload reportedly incorporated WNF-based process injection with process hollowing fallback, hidden VNC functionality aligned with banking fraud, browser profile cloning, credential access, keylogging, screenshot capture, webcam and audio capture, clipboard monitoring, hidden RDP, Windows Defender tampering, and multiple UAC bypass methods. Victimology and operational patterns indicate a strong concentration on South American public-sector organizations, especially Colombian government agencies, while broader campaigns have also affected private-sector targets. Although some reporting has characterized the actor as cyberespionage-oriented because of its government targeting, other assessments have judged the campaigns more consistent with financially motivated operations, particularly given the use of commodity RAT ecosystems and banking-fraud-enabling capabilities. Based on the supplied facts, financial gain is the clearest dominant motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
A recently patched security flaw affecting Windows NTLM has been exploited by malicious actors to leak NTLM hashes or user passwords and infiltrate systems since March 19, 2025. The flaw, CVE-2025-24054 (CVSS score: 6.5), is a hash disclosure spoofing bug that was fixed by Microsoft last month as part of its Patch Tuesday updates. The security flaw is assessed to be a variant of CVE-2024-43451 (CVSS score: 6.5), which was patched by Microsoft in November 2024 and has also been weaponized in the wild in attacks targeting Ukraine and Colombia by threat actors like UAC-0194 and Blind Eagle.
597 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The alert concerns Remcos RAT activity linked to APT-C-36.
Banking-fraud-focused threat actor targeting Colombian and broader Latin American victims using Spanish-language phishing, VBScript-to-PowerShell loader chains, commodity RATs, custom obfuscation, process injection, HVNC, browser profile cloning, and persistence disguised as 'Photo Studio'.
Referenced in a related article title as a threat actor associated with campaigns affecting South American organizations.
Targeted government entities in South America, especially Colombia, using spearphishing and RATs in campaigns combining espionage and financial motives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.