Understanding the Threat Behind Recent Digital Intrusions

A recent report revealed that over 80% of Latin American organizations faced targeted digital threats in the past year. Among these, a persistent threat actor has stood out for its sophisticated methods and regional focus.

Table of contents

An expert take by HakTechs, HakTechs.com Lead Analyst

This group, active since 2018, blends financial theft with espionage. Their campaigns often use deceptive tactics, like fake documents or hijacked cloud storage. Recent findings show they’ve expanded into critical sectors, including energy and transportation.

Security experts note their use of unique tools, such as Portuguese-language malware. These details help identify their operations. We’ll explore their methods and how to defend against them.

Key Takeaways

  • Active since 2018, focusing on Latin America
  • Combines financial theft with intelligence gathering
  • Targets government and private sector organizations
  • Uses cloud services and custom malware
  • Recent campaigns highlight evolving tactics

Introduction to APT-C-36 (Blind Eagle)

Security analysts have identified a growing threat targeting Latin American institutions. This actor, active since 2018, blends financial theft with espionage, focusing heavily on Colombia and Ecuador. Their methods include deceptive documents and geolocation-based filtering to evade detection.

Origins and Known Activity Timeline

First spotted in 2018, this group initially focused on Colombian tax agencies. By 2025, 87% of victims were in Colombia, per Kaspersky data. Recent Zscaler reports show expansion into Ecuador’s banking sector.

Notable campaigns include June 2025’s fake court summons impersonating judicial bodies. These lures tricked victims into downloading malware disguised as legal documents.

Geographic Focus and Primary Targets

Colombia remains the epicenter, with agencies like DIAN and the Attorney General’s Office repeatedly hit. Panama’s maritime sector also faced fraud via fake customs paperwork.

Geolocation filtering ensures only Latin American IPs access malicious links. URL shorteners block other regions, making detection harder for global defenders.

“Their sector distribution reveals a strategic shift: 34% government, 28% finance, and 19% energy.”

Zscaler ThreatLabz

Transportation firms were compromised using malware signed with legitimate ASUS certificates. This tactic bypasses security checks, showing the group’s adaptability.

APT-C-36’s Evolving Attack Methods in 2025

Recent cybersecurity investigations highlight a shift in digital intrusion strategies across Latin America. Threat actors now employ layered techniques to evade detection, combining social engineering with advanced file manipulation. These methods reflect a deliberate effort to exploit both human and technical vulnerabilities.

A complex, multi-stage cyber attack unfolding in a dystopian cityscape. In the foreground, a series of interconnected nodes and vectors representing the delivery chain - malware injection, data exfiltration, command and control. The middle ground features futuristic skyscrapers and infrastructure, their digital vulnerabilities exposed. In the background, an ominous skyline shrouded in digital fog, hinting at the broader scope of the attack. Dramatic chiaroscuro lighting casts deep shadows, creating a sense of tension and unease. The scene is rendered in a gritty, hyper-realistic style, emphasizing the gravity of the situation.

Phishing as the Primary Initial Vector

Deceptive emails remain the dominant entry point. A June 2025 campaign impersonated Colombian judicial bodies, luring victims with fake court summons. These emails contained malicious archives disguised as legal documents.

Researchers identified LHA and UUE archive formats, which bypass standard security scans. Once opened, a VBS downloader initiates the attack chain, leveraging process hollowing to inject malware into legitimate system processes.

Adaptation of Multi-Stage Payload Delivery

The group’s five-stage infection process begins with phishing and culminates in remote access trojan (RAT) deployment. Key innovations include:

  • Steganography: Base64-encoded .NET assemblies hidden within BMP files, with “HSOm” manipulation removing 150px borders to evade analysis.
  • DLL sideloading: ASUS-signed binaries exploited in June 2025 to load malicious libraries like Tyrone.dll.
  • Memory injection: HijackLoader variants inject QuasarRAT into memory, using port 9057 for command-and-control.

“Their payload execution relies on abusing trusted applications, making detection exceptionally challenging.”

Kaspersky GReAT Team

This modular approach allows rapid adaptation, with each stage designed to obscure the file’s malicious intent until final execution.

Recent Campaigns: Espionage and Financial Theft

Recent activity highlights a dual focus on espionage and financial crimes. Threat actors refined their techniques, blending social engineering with advanced technical exploits. Their campaigns now target both data and funds, leaving organizations vulnerable.

May 2025: Colombian Espionage with Portuguese-Laced Artifacts

Fake court summons PDFs circulated in Colombia, impersonating legal authorities. These documents contained embedded links to malicious ZIP archives. Once opened, they triggered a multi-stage attack chain.

Researchers noted Portuguese-language strings in the malware, a rare trait for Latin American operations. The payload used process hollowing to inject code into legitimate system processes. This evasion tactic made detection difficult.

June 2025: DLL Sideloading and HijackLoader Innovations

Attackers abused ASUS-signed binaries to sideload malicious DLLs. They leveraged legitimate IObit software to mask their file activities. Zscaler first observed HijackLoader in Q2, noting its modular plugin system.

The execution flow followed this pattern:

  • PDF lures → ZIP archives → Signed EXEs
  • Malicious DLLs loaded via trusted applications
  • C2 domains rotated using PublicVM.com

“HijackLoader’s flexibility allows rapid adaptation to security measures.”

Zscaler ThreatLabz

Spoofed Process Explorer entries further obscured the process, while AsyncRAT configurations were extracted dynamically.

Key Malware and Tools in Blind Eagle’s Arsenal

Security researchers have uncovered a sophisticated toolkit used in targeted intrusions across Latin America. These tools blend financial theft with espionage, adapting to evade detection while maximizing impact.

BlotchyQuasar: A Customized RAT for Banking Fraud

BlotchyQuasar enables remote access to compromised systems, focusing on banking trojan capabilities. Its keylogging module flushes stolen credentials every 15 seconds, ensuring frequent data exfiltration.

Researchers noted its use of code injection to hijack RDP sessions, mimicking user activity. This technique bypasses behavioral analysis tools by blending malicious actions with legitimate processes.

NjRAT and AsyncRAT: Modular Espionage Payloads

NjRAT, a modular RAT, delivers plugins as .NET assemblies. A June 2025 campaign exploited Discord’s CDN to stage payloads, hiding malicious code in seemingly benign files.

AsyncRAT operates on port 9057 for command-and-control. Its process hollowing technique delays execution until the final stage, evading sandbox analysis. Kaspersky observed obfuscated strings in Portuguese, a rare trait for such tools.

“These RATs leverage trusted applications to sideload malicious libraries, making them nearly invisible to endpoint protection.”

Zscaler ThreatLabz

Both tools abuse legal document decoys—Word macros trigger the infection chain, while Pastebin rotates C2 domains to avoid blacklisting.

Victimology: Who’s at Risk?

Energy and financial sectors report increasing incidents of targeted intrusions. Latin American organizations, especially in Colombia and Ecuador, face heightened risks. Government agencies and private firms alike struggle to defend against these evolving threats.

Government and Financial Sectors in Latin America

Colombian tax authorities and banking institutions remain primary victims. Fraudulent emails mimic official communications, like fake court summons or tax audits. These often contain malicious file attachments, such as UUE archives disguised as PDFs.

A sprawling cityscape of Latin American metropolises, with towering skyscrapers and bustling energy infrastructure. In the foreground, a complex network of power lines, transformers, and substations crisscross the urban landscape. Ominous shadows cast by the buildings suggest a sense of foreboding, as if a malicious cyber threat is lurking in the digital shadows. The middle ground depicts a team of cybersecurity professionals monitoring multiple screens, analyzing data and trying to defend against the looming threat. In the background, a swirling vortex of digital code and security alerts hints at the sophisticated nature of the attack, leaving the viewer with a sense of unease and the realization that the energy sector is a prime target for cyber criminals.

Panama’s maritime sector saw phishing campaigns impersonating the Canal Authority. Attackers used geolocation filtering to target local IPs exclusively. This tactic ensures only regional victims access the malicious links.

Emerging Targets in Energy and Transportation

The energy sector, including Ecopetrol’s pipeline networks, faced breaches in 2025. Compromised SCADA systems allowed unauthorized access to critical infrastructure. Fake fuel shipment documents delivered malware via .LHA archives.

Transportation firms encountered attacks through rail control systems. ASUS-signed loaders bypassed security checks, while maritime logistics faced spearphishing. Bogotá’s electric grid operators also reported incidents tied to fraudulent maintenance requests.

“Energy sector breaches rose 40% in 2025, with attackers exploiting outdated industrial control systems.”

Kaspersky ICS CERT

Tactics, Techniques, and Procedures (TTPs)

Digital intruders constantly refine their methods to bypass security measures. Their latest strategies combine technical sophistication with psychological manipulation, making detection increasingly difficult.

A dimly lit cybersecurity command center, with holographic displays projecting intricate diagrams of geolocation filtering and process hollowing techniques. Sleek, cutting-edge workstations are manned by a team of analysts, their faces illuminated by the soft glow of monitors. In the background, a large screen showcases a network topology, highlighting the complex interplay of systems and protocols. The atmosphere is tense, with a sense of urgency as the team works to unravel the tactics, techniques, and procedures employed by the elusive APT-C-36 hacker group. The scene is captured through a cinematic lens, emphasizing the high-stakes nature of the cyber threat landscape.

Geolocation Filtering and URL Shorteners

Attackers use smart filtering to target specific regions. They configure malicious links to work only for IP addresses from Latin America. This technique helps them avoid detection by international security teams.

URL shorteners play a key role in these operations. They mask the true destination while adding geolocation checks. Victims outside the target area see error messages instead of harmful content.

Process Hollowing and Steganography

Memory manipulation remains a favorite tool for evading detection. The process begins with creating a suspended instance of svchost.exe. Attackers then replace its code with malicious payloads using NTUnmapViewOfSection.

Steganography hides data in plain sight. Recent campaigns embed execution scripts within BMP files using ARGB pixel encoding. The HSOm technique removes borders to conceal the hidden file contents.

Key technical details include:

  • Base64-encoded payloads within PNG files
  • Gamma.dll converting integers to Unicode for obfuscation
  • VBScript abuse through WScript.Shell for persistence
  • .NET resource sections storing secondary payloads

“85% of recent incidents used steganography in BMP files, showing its effectiveness against automated scanners.”

Zscaler ThreatLabz

These methods demonstrate how attackers combine multiple techniques. As noted in recent security analysis, such layered approaches make defense particularly challenging.

Infrastructure and Command-and-Control (C2)

Behind every successful intrusion lies a carefully managed infrastructure. Threat actors rely on dynamic networks to maintain access and evade detection. These systems blend legitimate services with custom tools for stealth.

Dynamic DNS and Compromised Accounts

Attackers frequently abuse Google Drive as a resource for payload hosting. They upload malicious files to compromised business accounts. Dynamic DNS services like equipo[.]linkpc help rotate IP addresses.

The setup uses 3DES encryption with MD5-derived keys. Security teams found the string “qualityinfosolutions” in decrypted samples. This acts as the base for key generation.

Pastebin for C2 Domain Obfuscation

Pastebin serves as a critical tool for hiding server locations. The raw/XAfmb6xp paste contained encrypted C2 domains. Special ¡ delimiters separate encrypted segments for execution.

Here’s how the workflow operates:

  • Base64-encoded strings in pastes
  • 3DES decryption using MD5 keys
  • Domain resolution every 24 hours
  • Pattern: pastebin[.]com/raw/XXXX

“Pastebin rotation cycles complicate tracking—we see new pastes every day with fresh domains.”

Zscaler ThreatLabz

This method allows quick changes if domains get blocked. The code automatically fetches updates, ensuring continuous access during an attack.

Attribution and Threat Actor Profile

Brazilian cybersecurity forums reveal underground partnerships fueling digital threats. These networks blend local expertise with global tools, creating a persistent risk for organizations. We analyze their connections and operational methods.

Portuguese-speaking developer forums host ads for malware services. Kaspersky identified Brazilian image hosts distributing malicious file payloads. These platforms mask illegal activities behind legitimate-looking uploads.

Key collaboration patterns include:

  • Malware-as-a-service: HijackLoader developers rent tools for $500/month.
  • Exploit kit subscriptions targeting .NET vulnerabilities.
  • Spanish-to-Portuguese translation services for phishing lures.
Service Price Platform
Custom RATs $1,200 Hidden Telegram channels
Exploit Kits $300/week Dark web forums
Insider Access Bitcoin Encrypted email

Collaboration with Third-Party Hackers

Zscaler traced Bitcoin payments from Latin America to Eastern Europe. These funds likely compensate for code customization or infrastructure support. One campaign used Polish proxies to obscure C2 servers.

“Insider threats amplify risks—employees sell access for as little as $200.”

Kaspersky Global Research Team

Attackers increasingly outsource execution phases. Local recruits handle phishing, while overseas experts manage payload deployment. This division of labor complicates attribution.

Defensive Measures Against Blind Eagle Attacks

Proactive security measures can significantly reduce intrusion risks. Organizations must implement both technical controls and employee training to counter sophisticated threats. We outline critical steps to detect and block common attack vectors.

Detecting Phishing Lures and Malicious Attachments

Email remains the primary entry point for intrusions. Watch for these red flags in messages:

  • Unusual sender addresses mimicking government agencies
  • Compressed attachments with double extensions (.pdf.exe)
  • Portuguese or Spanish language anomalies in documents
Indicator Action
Client.exe (SHA-256) 5a3f…d21c → Block
Port 9057 traffic Drop outbound connections
Gamma.dll Quarantine from startup folders

“Memory analysis reveals 73% of successful intrusions begin with process hollowing of svchost.exe.”

Zscaler ThreatLabz

Mitigating RAT-Based Infiltrations

Remote access tools require specific countermeasures. Hunt for these artifacts:

  • Unusual %APPDATA%\GPrets directories
  • Keystroke entropy deviations in user sessions
  • HSOm-altered bitmap files in temp folders

Deploy AsyncRAT config extractors to analyze captured samples. Monitor process memory for unexpected .NET assembly loads. Block Pastebin domains used for C2 rotation.

Effective defense combines:

  1. Network traffic analysis for 3DES patterns
  2. Endpoint detection for malware persistence
  3. User training to recognize social engineering

Conclusion: The Persistent Threat of APT-C-36

Organizations across Latin America face escalating digital threats from sophisticated actors. The shift from njRAT to BlotchyQuasar highlights evolving malware capabilities, targeting financial and government sectors.

Colombian infrastructure remains vulnerable, with campaigns exploiting outdated systems. Energy firms now face heightened risks, as attackers manipulate file formats like UUE archives.

To counter these attack methods, we recommend multi-factor authentication and regional threat intelligence sharing. Continuous monitoring of C2 domains and process hollowing detection are critical.

Portuguese-language lures suggest expanding operations. Proactive defense and collaboration will be key to mitigating this persistent threat actor.

FAQ

What industries are most at risk from Blind Eagle attacks?

Government agencies, financial institutions, and critical infrastructure sectors in Latin America face the highest risk. Recent campaigns also show growing interest in energy and transportation networks.

How does Blind Eagle typically gain initial access to systems?

The group primarily uses phishing emails with malicious attachments or links. These often impersonate legitimate organizations and contain weaponized documents or archive files.

What malware tools does this group frequently deploy?

Their arsenal includes customized remote access trojans like BlotchyQuasar for financial theft, along with modular espionage tools such as NjRAT and AsyncRAT for persistent access.

Why is Blind Eagle difficult to detect?

They employ advanced evasion techniques including geolocation filtering, URL shorteners, process hollowing, and steganography to hide malicious activity within normal network traffic.

What makes their 2025 campaigns different from previous years?

Recent operations show refined tactics including Portuguese-language lures targeting Colombian entities, DLL sideloading techniques, and HijackLoader innovations for bypassing security controls.

How does the group maintain communication with compromised systems?

They leverage dynamic DNS services, hijacked cloud storage accounts (especially Google Drive), and Pastebin for command-and-control server obfuscation to avoid detection.

What defensive measures work against these attacks?

Effective countermeasures include advanced email filtering, attachment sandboxing, endpoint detection for RAT behavior, and network monitoring for suspicious C2 communications.

Are there known connections to other threat actors?

Intelligence suggests collaboration with South American cybercriminal networks and occasional partnerships with third-party hackers for specialized components of their operations.