Blind Eagle is a long-running South America-focused threat actor, active since at least 2018, that has been tracked under aliases including TAG-144, AguilaCiega, APT-C-36, APT-Q-98, and Red Akodon. The actor is strongly associated with campaigns centered on Colombia and has persistently targeted Colombian government entities at local, municipal, and federal levels, while also conducting operations against victims in other South American countries. Additional targeting has included financial institutions, petroleum and energy organizations, education, healthcare, manufacturing, and professional services. The group is known for phishing- and spearphishing-led intrusions that impersonate government and judicial institutions, often using themes such as lawsuits, court summonses, debt collection, and official notifications. Delivery chains have used links to cloud-hosted lure documents, compressed payloads staged on legitimate internet services, and malicious attachments that redirect victims to follow-on downloads. The actor has repeatedly relied on commodity and cracked remote access trojans, including AsyncRAT, RemcosRAT, QuasarRAT, XWorm, DcRAT, LimeRAT, njRAT, and BitRAT, and has also used crypters and crypter-as-a-service tooling to hinder detection. Observed tradecraft includes DLL sideloading or hijacking through legitimate applications, process injection into trusted Windows binaries, persistence via scheduled tasks and startup shortcuts, Windows Defender exclusion changes, attempts to interfere with UAC-related mechanisms, and use of steganography to conceal payloads in image files. Follow-on activity has included deployment of additional trojans and credential-focused surveillance capabilities such as keylogging and browser monitoring. The actor has also used compromised email accounts to support spearphishing and has employed geo-fencing and other defense-evasion measures to restrict access to malicious infrastructure based on victim geography. Blind Eagle's operations indicate a blend of credential theft and surveillance. Reporting has characterized its motivation as mixed between financially driven activity and espionage-like collection, with repeated emphasis on theft of banking details, email and social media credentials, and access to organizational portals. Based on the available facts, the actor is best understood as a Colombia-centric intrusion set using commodity malware at scale for credential theft, surveillance, and broader post-compromise access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster/group referenced as linked to TAG-144; no additional operational details provided in the excerpt beyond the asserted linkage.
Credential theft and remote-access operations primarily against Colombian users via phishing lures themed as lawsuits/judicial summons. Uses cloud/file-hosting (Google Drive/OneDrive) and GitHub for payload delivery, DLL hijacking to inject AsyncRAT into MSBuild.exe, establishes persistence (Start Menu shortcuts + scheduled task), weakens defenses (Defender exclusions, UAC bypass attempt via cmstp), and deploys multiple RATs (AsyncRAT, Remcos, Quasar, XWorm) plus Neshta to infect EXEs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.