216.73.217.22

TAG-144's Persistent Grip on South American Organizations

· Published 26/08/2025 15:21 · Modified 26/08/2025 19:38

Export JSON

Essential information

Published
26/08/2025 15:21
Modified
26/08/2025 19:38
Tags
2025-08-26 asyncrat bitrat blotchyquasar dcrat limerat njrat quasarrat remcos rat south america tag-144 xworm
Related entities
1 intrusion sets (apt), 12 malware, 11 others

Description

Insikt Group has identified five distinct activity clusters linked to (Blind Eagle), targeting primarily Colombian government entities across local, municipal, and federal levels throughout 2024 and 2025. The clusters share similar tactics, techniques, and procedures (TTPs) such as using open-source and cracked remote access trojans (RATs), dynamic domain providers, and legitimate internet services (LIS) for staging. However, they differ in infrastructure, malware deployment, and operational methods. The group maintains an extensive operational infrastructure, employs various RATs, and uses multi-stage infection chains. 's primary focus appears to be credential theft and espionage, with evidence linking it to Red Akodon and compromised Colombian government email accounts used in spearphishing campaigns.

External references