Blind Eagle, a.k.a. APT-C-36, Águila Ciega (ATT&CK Group ID: G0099), is a Spanish-speaking threat actor that has been active since at least 2018.1 The group is believed to be based in South America, given their use of regional Spanish dialects and intimate knowledge of government agencies and other local institutions in the region. The group tends to target Colombia-based institutions, including entities in the financial, manufacturing, and petroleum sectors.2 However, this threat actor has also executed operations against victims throughout South America, Europe, the US, and Australia.3 4 While Blind Eagle tends to be largely opportunistic in their motives, though they have conducted espionage operations as well.5
Blind Eagle generally relies on commodity RATs, including Imminent Monitor, BitRAT, QuasarRAT, AsyncRAT, LimeRAT, and RemcosRAT.6 7 8 This threat actor's campaigns often leverage spearphishing for initial access and the deployment of encrypted payloads.2 Additional common TTPs used by this threat actor include: spearphishing, use of malicious macros, process injection, and other LOTL techniques.5 9 The group also employs relatively strict targeting, and has been known to link-shortening services that geoloate victims.3
We 💖 feedback! Let us know how using ATT&CK Evaluation results has helped you and what we can do better.
Email: evals@mitre-engenuity.org
Twitter: https://twitter.com/MITREengenuity
LinkedIn: https://www.linkedin.com/company/mitre-engenuity/