Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
ToolQuasarRAT | APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions. |
| T1021.001 Remote Desktop Protocol |
MalwarenjRAT | njRAT has a module for performing remote desktop access. |
| T1027 Obfuscated Files or Information |
GroupAPT-C-36 | APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.013 Encrypted/Encoded File |
GroupAPT-C-36 | APT-C-36 has used encoded and obfuscated files, images, and executables. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT-C-36 | APT-C-36 has disguised malicious executables to appear as legitimate files. |
| T1041 Exfiltration Over C2 Channel |
MalwarenjRAT | njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information. |
| T1055.012 Process Hollowing |
GroupAPT-C-36 | APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1059.001 PowerShell |
GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.005 Visual Basic |
GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1105 Ingress Tool Transfer |
MalwarenjRAT | njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies. |
| T1113 Screen Capture |
MalwarenjRAT | njRAT can capture screenshots of the victim’s machines. |
| T1204.001 Malicious Link |
GroupAPT-C-36 | APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads. |
| T1480 Execution Guardrails |
GroupAPT-C-36 | APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites. |
| T1555.003 Credentials from Web Browsers |
ToolQuasarRAT | QuasarRAT can obtain passwords from common web browsers. |
| T1566.001 Spearphishing Attachment |
GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| T1566.002 Spearphishing Link |
GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1574.001 DLL |
GroupAPT-C-36 | APT-C-36 has used side-loading to execute the HijackLoader payload. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1587.001 Malware |
GroupAPT-C-36 | APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT. |
| T1608.001 Upload Malware |
GroupAPT-C-36 | APT-C-36 has staged malware implants on group-owned repositories and sites. |
| T1683.001 Written Content |
GroupAPT-C-36 | APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.