Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
ToolRemcos | Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis. |
| T1027.002 Software Packing |
MalwareHeartCrypt | HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.013 Encrypted/Encoded File |
MalwarePureCrypter | PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation. |
| T1033 System Owner/User Discovery |
MalwarePureCrypter | PureCrypter can retrieve the username from targeted machines. |
| T1053.005 Scheduled Task |
MalwarePureCrypter | PureCrypter can maintain persistence with scheduled tasks. |
| T1057 Process Discovery |
MalwarePureCrypter | PureCrypter can enumerate processes on compromised hosts. |
| T1059.001 PowerShell |
MalwarePureCrypter | PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete. |
| T1082 System Information Discovery |
MalwarePureCrypter | PureCrypter can enumerate a targeted system's SerialNumber and Version. |
| T1105 Ingress Tool Transfer |
MalwarePureCrypter | PureCrypter can download additional payloads for execution on the compromised host. |
| T1132.001 Standard Encoding |
ToolRemcos | Remcos can serialize collected data with Protobuf. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePureCrypter | PureCrypter can decrypt downloaded resources and parse internal files to determine its settings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHeartCrypt | HeartCrypt can decrypt payloads prior to execution. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1518.001 Security Software Discovery |
MalwarePureCrypter | PureCrypter can identify installed antivirus solutions. |
| T1564.003 Hidden Window |
MalwarePureCrypter | PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines. |
| T1564.003 Hidden Window |
ToolRemcos | Remcos can set `ProcessWindowStyle.Hidden` to hide windows. |
| T1566.002 Spearphishing Link |
GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| T1568 Dynamic Resolution |
ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1573.001 Symmetric Cryptography |
MalwarePureCrypter | PureCrypter can use AES to encrypt system information sent to the C2. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1588.001 Malware |
GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| T1588.002 Tool |
GroupAPT-C-36 | APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.