Who is Blind Eagle? A notorious cyber threat actor known as Blind Eagle (APT-C-36) has been actively targeting entities in Colombia, Ecuador, Chile, Panama, and other Latin American nations since 2018.
Who are the Targets?
- Government institutions
- Financial companies
- Energy and oil & gas sectors
Their Tactics:
- Spear-phishing emails mimicking government and financial entities
- Deployment of Remote Access Trojans (RATs) like AsyncRAT, BitRAT, and NjRAT
- Use of Ande Loader to spread malware
- Geographical redirection to avoid detection
How They Operate:
- Phishing emails contain malicious links or attachments.
- Users are redirected based on their location.
- Malicious scripts download second-stage payloads.
- The RATs execute in memory to evade detection.
What Makes Them Dangerous? Blind Eagle's adaptability allows them to switch between cyber espionage and financial theft with ease. They continue to update their techniques, making them a persistent threat in the region