Blind Spider is a financially motivated cybercriminal threat actor tracked by CrowdStrike as one of the major operators active in Latin America. The group is also referred to in some reporting as Blind Eagle. It has been associated with operations in the region and has been cited among threat actors that have incorporated AI into aspects of their activity. Available reporting places Blind Spider within the broader Latin American e-crime ecosystem rather than as a nation-state actor. Blind Spider has been discussed in connection with malware delivery activity affecting parts of Latin America, but attribution boundaries are important: HeartCrypt-related campaigns were specifically assessed to involve multiple distinct threat actors and not to be attributable as a whole to Blind Spider. The overlap noted between some HeartCrypt cases and Blind Spider was limited to geography, while differences in payloads, injection methods, and targeted locations supported separation of those activities. High-confidence public information in the supplied material is limited. Blind Spider is identified as a major financially motivated operator targeting Latin America, but the material does not directly substantiate a detailed set of tactics, techniques, victim sectors, or country-by-country targeting beyond regional focus. As such, only broad, corroborated attributes can be stated with confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as leveraging AI in operations (no additional operational details provided in the content).
Financially motivated criminal activity cluster identified as a major operator in Latin America; described as based in LATAM or primarily focused on targets in the region.
Referenced as a possible but ultimately unconfirmed affiliate or user of the HeartCrypt packer-as-a-service operation, with geographic overlap in targeting, particularly Colombia.
Referenced as a distinct threat actor initially suspected of being behind HeartCrypt-related activity due to geographic target overlap, but the article concludes the broader HeartCrypt activity involved multiple threat actors rather than Blind Spider alone.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.