ATT&CKReferencesCheck Point Blind Eagle MAR 2025

Check Point Blind Eagle MAR 2025

Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
ToolRemcos

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

T1027.002
Software Packing
MalwareHeartCrypt

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.013
Encrypted/Encoded File
MalwarePureCrypter

PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation.

T1033
System Owner/User Discovery
MalwarePureCrypter

PureCrypter can retrieve the username from targeted machines.

T1053.005
Scheduled Task
MalwarePureCrypter

PureCrypter can maintain persistence with scheduled tasks.

T1057
Process Discovery
MalwarePureCrypter

PureCrypter can enumerate processes on compromised hosts.

T1059.001
PowerShell
MalwarePureCrypter

PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete.

T1082
System Information Discovery
MalwarePureCrypter

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1105
Ingress Tool Transfer
MalwarePureCrypter

PureCrypter can download additional payloads for execution on the compromised host.

T1132.001
Standard Encoding
ToolRemcos

Remcos can serialize collected data with Protobuf.

T1140
Deobfuscate/Decode Files or Information
MalwarePureCrypter

PureCrypter can decrypt downloaded resources and parse internal files to determine its settings.

T1140
Deobfuscate/Decode Files or Information
MalwareHeartCrypt

HeartCrypt can decrypt payloads prior to execution.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1518.001
Security Software Discovery
MalwarePureCrypter

PureCrypter can identify installed antivirus solutions.

T1564.003
Hidden Window
MalwarePureCrypter

PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines.

T1564.003
Hidden Window
ToolRemcos

Remcos can set `ProcessWindowStyle.Hidden` to hide windows.

T1566.002
Spearphishing Link
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

T1568
Dynamic Resolution
ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1573.001
Symmetric Cryptography
MalwarePureCrypter

PureCrypter can use AES to encrypt system information sent to the C2.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1588.002
Tool
GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.