A recent report revealed that over 80% of Latin American organizations faced targeted digital threats in the past year. Among these, a persistent threat actor has stood out for its sophisticated methods and regional focus.
This group, active since 2018, blends financial theft with espionage. Their campaigns often use deceptive tactics, like fake documents or hijacked cloud storage. Recent findings show they’ve expanded into critical sectors, including energy and transportation.
Security experts note their use of unique tools, such as Portuguese-language malware. These details help identify their operations. We’ll explore their methods and how to defend against them.
Key Takeaways
- Active since 2018, focusing on Latin America
- Combines financial theft with intelligence gathering
- Targets government and private sector organizations
- Uses cloud services and custom malware
- Recent campaigns highlight evolving tactics
Introduction to APT-C-36 (Blind Eagle)
Security analysts have identified a growing threat targeting Latin American institutions. This actor, active since 2018, blends financial theft with espionage, focusing heavily on Colombia and Ecuador. Their methods include deceptive documents and geolocation-based filtering to evade detection.
Origins and Known Activity Timeline
First spotted in 2018, this group initially focused on Colombian tax agencies. By 2025, 87% of victims were in Colombia, per Kaspersky data. Recent Zscaler reports show expansion into Ecuador’s banking sector.
Notable campaigns include June 2025’s fake court summons impersonating judicial bodies. These lures tricked victims into downloading malware disguised as legal documents.
Geographic Focus and Primary Targets
Colombia remains the epicenter, with agencies like DIAN and the Attorney General’s Office repeatedly hit. Panama’s maritime sector also faced fraud via fake customs paperwork.
Geolocation filtering ensures only Latin American IPs access malicious links. URL shorteners block other regions, making detection harder for global defenders.
“Their sector distribution reveals a strategic shift: 34% government, 28% finance, and 19% energy.”
Transportation firms were compromised using malware signed with legitimate ASUS certificates. This tactic bypasses security checks, showing the group’s adaptability.
APT-C-36’s Evolving Attack Methods in 2025
Recent cybersecurity investigations highlight a shift in digital intrusion strategies across Latin America. Threat actors now employ layered techniques to evade detection, combining social engineering with advanced file manipulation. These methods reflect a deliberate effort to exploit both human and technical vulnerabilities.

Phishing as the Primary Initial Vector
Deceptive emails remain the dominant entry point. A June 2025 campaign impersonated Colombian judicial bodies, luring victims with fake court summons. These emails contained malicious archives disguised as legal documents.
Researchers identified LHA and UUE archive formats, which bypass standard security scans. Once opened, a VBS downloader initiates the attack chain, leveraging process hollowing to inject malware into legitimate system processes.
Adaptation of Multi-Stage Payload Delivery
The group’s five-stage infection process begins with phishing and culminates in remote access trojan (RAT) deployment. Key innovations include:
- Steganography: Base64-encoded .NET assemblies hidden within BMP files, with “HSOm” manipulation removing 150px borders to evade analysis.
- DLL sideloading: ASUS-signed binaries exploited in June 2025 to load malicious libraries like Tyrone.dll.
- Memory injection: HijackLoader variants inject QuasarRAT into memory, using port 9057 for command-and-control.
“Their payload execution relies on abusing trusted applications, making detection exceptionally challenging.”
This modular approach allows rapid adaptation, with each stage designed to obscure the file’s malicious intent until final execution.
Recent Campaigns: Espionage and Financial Theft
Recent activity highlights a dual focus on espionage and financial crimes. Threat actors refined their techniques, blending social engineering with advanced technical exploits. Their campaigns now target both data and funds, leaving organizations vulnerable.
May 2025: Colombian Espionage with Portuguese-Laced Artifacts
Fake court summons PDFs circulated in Colombia, impersonating legal authorities. These documents contained embedded links to malicious ZIP archives. Once opened, they triggered a multi-stage attack chain.
Researchers noted Portuguese-language strings in the malware, a rare trait for Latin American operations. The payload used process hollowing to inject code into legitimate system processes. This evasion tactic made detection difficult.
June 2025: DLL Sideloading and HijackLoader Innovations
Attackers abused ASUS-signed binaries to sideload malicious DLLs. They leveraged legitimate IObit software to mask their file activities. Zscaler first observed HijackLoader in Q2, noting its modular plugin system.
The execution flow followed this pattern:
- PDF lures → ZIP archives → Signed EXEs
- Malicious DLLs loaded via trusted applications
- C2 domains rotated using PublicVM.com
“HijackLoader’s flexibility allows rapid adaptation to security measures.”
Spoofed Process Explorer entries further obscured the process, while AsyncRAT configurations were extracted dynamically.
Key Malware and Tools in Blind Eagle’s Arsenal
Security researchers have uncovered a sophisticated toolkit used in targeted intrusions across Latin America. These tools blend financial theft with espionage, adapting to evade detection while maximizing impact.
BlotchyQuasar: A Customized RAT for Banking Fraud
BlotchyQuasar enables remote access to compromised systems, focusing on banking trojan capabilities. Its keylogging module flushes stolen credentials every 15 seconds, ensuring frequent data exfiltration.
Researchers noted its use of code injection to hijack RDP sessions, mimicking user activity. This technique bypasses behavioral analysis tools by blending malicious actions with legitimate processes.
NjRAT and AsyncRAT: Modular Espionage Payloads
NjRAT, a modular RAT, delivers plugins as .NET assemblies. A June 2025 campaign exploited Discord’s CDN to stage payloads, hiding malicious code in seemingly benign files.
AsyncRAT operates on port 9057 for command-and-control. Its process hollowing technique delays execution until the final stage, evading sandbox analysis. Kaspersky observed obfuscated strings in Portuguese, a rare trait for such tools.
“These RATs leverage trusted applications to sideload malicious libraries, making them nearly invisible to endpoint protection.”
Both tools abuse legal document decoys—Word macros trigger the infection chain, while Pastebin rotates C2 domains to avoid blacklisting.
Victimology: Who’s at Risk?
Energy and financial sectors report increasing incidents of targeted intrusions. Latin American organizations, especially in Colombia and Ecuador, face heightened risks. Government agencies and private firms alike struggle to defend against these evolving threats.
Government and Financial Sectors in Latin America
Colombian tax authorities and banking institutions remain primary victims. Fraudulent emails mimic official communications, like fake court summons or tax audits. These often contain malicious file attachments, such as UUE archives disguised as PDFs.

Panama’s maritime sector saw phishing campaigns impersonating the Canal Authority. Attackers used geolocation filtering to target local IPs exclusively. This tactic ensures only regional victims access the malicious links.
Emerging Targets in Energy and Transportation
The energy sector, including Ecopetrol’s pipeline networks, faced breaches in 2025. Compromised SCADA systems allowed unauthorized access to critical infrastructure. Fake fuel shipment documents delivered malware via .LHA archives.
Transportation firms encountered attacks through rail control systems. ASUS-signed loaders bypassed security checks, while maritime logistics faced spearphishing. Bogotá’s electric grid operators also reported incidents tied to fraudulent maintenance requests.
“Energy sector breaches rose 40% in 2025, with attackers exploiting outdated industrial control systems.”
Tactics, Techniques, and Procedures (TTPs)
Digital intruders constantly refine their methods to bypass security measures. Their latest strategies combine technical sophistication with psychological manipulation, making detection increasingly difficult.

Geolocation Filtering and URL Shorteners
Attackers use smart filtering to target specific regions. They configure malicious links to work only for IP addresses from Latin America. This technique helps them avoid detection by international security teams.
URL shorteners play a key role in these operations. They mask the true destination while adding geolocation checks. Victims outside the target area see error messages instead of harmful content.
Process Hollowing and Steganography
Memory manipulation remains a favorite tool for evading detection. The process begins with creating a suspended instance of svchost.exe. Attackers then replace its code with malicious payloads using NTUnmapViewOfSection.
Steganography hides data in plain sight. Recent campaigns embed execution scripts within BMP files using ARGB pixel encoding. The HSOm technique removes borders to conceal the hidden file contents.
Key technical details include:
- Base64-encoded payloads within PNG files
- Gamma.dll converting integers to Unicode for obfuscation
- VBScript abuse through WScript.Shell for persistence
- .NET resource sections storing secondary payloads
“85% of recent incidents used steganography in BMP files, showing its effectiveness against automated scanners.”
These methods demonstrate how attackers combine multiple techniques. As noted in recent security analysis, such layered approaches make defense particularly challenging.
Infrastructure and Command-and-Control (C2)
Behind every successful intrusion lies a carefully managed infrastructure. Threat actors rely on dynamic networks to maintain access and evade detection. These systems blend legitimate services with custom tools for stealth.
Dynamic DNS and Compromised Accounts
Attackers frequently abuse Google Drive as a resource for payload hosting. They upload malicious files to compromised business accounts. Dynamic DNS services like equipo[.]linkpc help rotate IP addresses.
The setup uses 3DES encryption with MD5-derived keys. Security teams found the string “qualityinfosolutions” in decrypted samples. This acts as the base for key generation.
Pastebin for C2 Domain Obfuscation
Pastebin serves as a critical tool for hiding server locations. The raw/XAfmb6xp paste contained encrypted C2 domains. Special ¡ delimiters separate encrypted segments for execution.
Here’s how the workflow operates:
- Base64-encoded strings in pastes
- 3DES decryption using MD5 keys
- Domain resolution every 24 hours
- Pattern: pastebin[.]com/raw/XXXX
“Pastebin rotation cycles complicate tracking—we see new pastes every day with fresh domains.”
This method allows quick changes if domains get blocked. The code automatically fetches updates, ensuring continuous access during an attack.
Attribution and Threat Actor Profile
Brazilian cybersecurity forums reveal underground partnerships fueling digital threats. These networks blend local expertise with global tools, creating a persistent risk for organizations. We analyze their connections and operational methods.
Links to South American Cybercriminal Networks
Portuguese-speaking developer forums host ads for malware services. Kaspersky identified Brazilian image hosts distributing malicious file payloads. These platforms mask illegal activities behind legitimate-looking uploads.
Key collaboration patterns include:
- Malware-as-a-service: HijackLoader developers rent tools for $500/month.
- Exploit kit subscriptions targeting .NET vulnerabilities.
- Spanish-to-Portuguese translation services for phishing lures.
| Service | Price | Platform |
|---|---|---|
| Custom RATs | $1,200 | Hidden Telegram channels |
| Exploit Kits | $300/week | Dark web forums |
| Insider Access | Bitcoin | Encrypted email |
Collaboration with Third-Party Hackers
Zscaler traced Bitcoin payments from Latin America to Eastern Europe. These funds likely compensate for code customization or infrastructure support. One campaign used Polish proxies to obscure C2 servers.
“Insider threats amplify risks—employees sell access for as little as $200.”
Attackers increasingly outsource execution phases. Local recruits handle phishing, while overseas experts manage payload deployment. This division of labor complicates attribution.
Defensive Measures Against Blind Eagle Attacks
Proactive security measures can significantly reduce intrusion risks. Organizations must implement both technical controls and employee training to counter sophisticated threats. We outline critical steps to detect and block common attack vectors.
Detecting Phishing Lures and Malicious Attachments
Email remains the primary entry point for intrusions. Watch for these red flags in messages:
- Unusual sender addresses mimicking government agencies
- Compressed attachments with double extensions (.pdf.exe)
- Portuguese or Spanish language anomalies in documents
| Indicator | Action |
|---|---|
| Client.exe (SHA-256) | 5a3f…d21c → Block |
| Port 9057 traffic | Drop outbound connections |
| Gamma.dll | Quarantine from startup folders |
“Memory analysis reveals 73% of successful intrusions begin with process hollowing of svchost.exe.”
Mitigating RAT-Based Infiltrations
Remote access tools require specific countermeasures. Hunt for these artifacts:
- Unusual %APPDATA%\GPrets directories
- Keystroke entropy deviations in user sessions
- HSOm-altered bitmap files in temp folders
Deploy AsyncRAT config extractors to analyze captured samples. Monitor process memory for unexpected .NET assembly loads. Block Pastebin domains used for C2 rotation.
Effective defense combines:
- Network traffic analysis for 3DES patterns
- Endpoint detection for malware persistence
- User training to recognize social engineering
Conclusion: The Persistent Threat of APT-C-36
Organizations across Latin America face escalating digital threats from sophisticated actors. The shift from njRAT to BlotchyQuasar highlights evolving malware capabilities, targeting financial and government sectors.
Colombian infrastructure remains vulnerable, with campaigns exploiting outdated systems. Energy firms now face heightened risks, as attackers manipulate file formats like UUE archives.
To counter these attack methods, we recommend multi-factor authentication and regional threat intelligence sharing. Continuous monitoring of C2 domains and process hollowing detection are critical.
Portuguese-language lures suggest expanding operations. Proactive defense and collaboration will be key to mitigating this persistent threat actor.