Names Blind Eagle (Qihoo 360) APT-C-36 (Qihoo 360) AguilaCiega (?) APT-Q-98 (?) Country Colombia Colombia Motivation Information theft and espionage, Financial crime First seen 2018 Description (Qihoo 360) Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government institutions as well as important corporations in financial sector, petroleum industry, professional manufacturing, etc. Till this moment, 360 Threat Intelligence Center captured 29 bait documents, 62 Trojan samples and multiple related malicious domains in total. Attackers are targeting Windows platform and aiming at government institutions as well as big companies in Colombia. Observed Sectors: Education, Energy, Financial, Government, Healthcare, Manufacturing, Transportation and large domestic companies and multinational corporation branches. Countries: Chile, Colombia, Ecuador, Panama, Spain, USA. Tools used AsyncRAT, BitRAT, BlotchyQuasar, Imminent Monitor RAT, njRAT, LimeRAT, RemcosRAT, Warzone RAT. Operations performed Sep 2021 APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs 2022 BlindEagle Targeting Ecuador With Sharpened Tools Feb 2023 Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia's Judiciary, Financial, Public, and Law Enforcement Entities Mar 2023 BlindEagle flying high in Latin America Jul 2023 Blind Eagle's North American Journey Jun 2024 BlindEagle Targets Colombian Insurance Sector with BlotchyQuasar Information MITRE ATT&CK Last change to this card: 23 October 2024