Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
MalwareCaminho | Caminho can use junk code for obfuscation. |
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.013 Encrypted/Encoded File |
ToolDCRAT | The DCRAT configuration file is encrypted using AES-256. |
| T1027.013 Encrypted/Encoded File |
MalwareCaminho | Caminho can use code flattening for payload obfuscation. |
| T1047 Windows Management Instrumentation |
GroupAPT-C-36 | APT-C-36 has used WMI to execute PowerShell. |
| T1055.012 Process Hollowing |
MalwareCaminho | Caminho has launched and hollowed out MSBuild.exe to host malicious code. |
| T1056.001 Keylogging |
ToolDCRAT | DCRAT can log keystrokes on targeted systems. |
| T1059.001 PowerShell |
GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.007 JavaScript |
GroupAPT-C-36 | APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads. |
| T1105 Ingress Tool Transfer |
MalwareCaminho | Caminho has the ability to download files onto compromised hosts. |
| T1106 Native API |
MalwareCaminho | Caminho can use `System.Net.WebClient.downloadString()` for file download. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCaminho | Caminho can deobfuscate downloaded files prior to execution. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1534 Internal Spearphishing |
GroupAPT-C-36 | APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization. |
| T1564.003 Hidden Window |
GroupAPT-C-36 | APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1573.002 Asymmetric Cryptography |
ToolDCRAT | DCRAT can use certificate-based authentication for C2 servers. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1586.002 Email Accounts |
GroupAPT-C-36 | APT-C-36 has regularly used compromised email accounts in spearphishing campaigns. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
| T1685 Disable or Modify Tools |
ToolDCRAT | DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.