Threat group.View on attack.mitre.org
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027.003 Steganography |
APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.013 Encrypted/Encoded File |
APT-C-36 has used encoded and obfuscated files, images, and executables. |
| T1027.016 Junk Code Insertion |
APT-C-36 has used junk characters to obfuscate malicious scripts. |
| T1036.004 Masquerade Task or Service |
APT-C-36 has disguised its scheduled tasks as those used by Google. |
| T1036.005 Match Legitimate Resource Name or Location |
APT-C-36 has disguised malicious executables to appear as legitimate files. |
| T1047 Windows Management Instrumentation |
APT-C-36 has used WMI to execute PowerShell. |
| T1053.005 Scheduled Task |
APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google. |
| T1055.012 Process Hollowing |
APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. |
| T1059.001 PowerShell |
APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.005 Visual Basic |
APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1059.007 JavaScript |
APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads. |
| T1105 Ingress Tool Transfer |
APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened. |
| T1133 External Remote Services |
APT-C-36 has used VPNs in their operational infrastructure. |
| T1204.001 Malicious Link |
APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.