ATT&CKReferencesKaspersky BlindEagle AUG 2024

Kaspersky BlindEagle AUG 2024

Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1010
Application Window Discovery
ToolQuasarRAT

APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions.

T1021.001
Remote Desktop Protocol
MalwarenjRAT

njRAT has a module for performing remote desktop access.

T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.013
Encrypted/Encoded File
GroupAPT-C-36

APT-C-36 has used encoded and obfuscated files, images, and executables.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT-C-36

APT-C-36 has disguised malicious executables to appear as legitimate files.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1055.012
Process Hollowing
GroupAPT-C-36

APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1059.001
PowerShell
GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

T1113
Screen Capture
MalwarenjRAT

njRAT can capture screenshots of the victim’s machines.

T1204.001
Malicious Link
GroupAPT-C-36

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

T1480
Execution Guardrails
GroupAPT-C-36

APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1566.001
Spearphishing Attachment
GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

T1566.002
Spearphishing Link
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1574.001
DLL
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1587.001
Malware
GroupAPT-C-36

APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1683.001
Written Content
GroupAPT-C-36

APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads.

T1684.001
Impersonation
GroupAPT-C-36

APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.