216.73.216.26

APT-C-36 (Blind Eagle) continues to target Colombia

· Published 17/12/2024 15:58 · Modified 17/12/2024 16:34

Export JSON

Essential information

Published
17/12/2024 15:58
Modified
17/12/2024 16:34
Tags
2024-12-17 asyncrat government impersonation heaven's gate svg bait
Related entities
4 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 7 others

Description

APT-C-36, known as Blind Eagle, is suspected to originate from South America and primarily targets Colombia and other South American countries. Since October 2024, the group has been using more diverse and complex attack methods against Colombian entities. Their tactics involve multi-stage payload delivery and injection, memory execution to conceal traces, and anti-debugging techniques. The attack process includes using SVG files as bait, impersonating Colombian government communications, and ultimately deploying the client for remote control. The group's technical capabilities have notably improved, incorporating techniques like 'Heaven's Gate' to evade analysis.

External references