APT-C-36
Also reported as Blind Eagle, AguilaCiega, APT-Q-98 and TAG-144. Linked to Colombia by one source.
Reports per quarter
Techniques seen in the last two years
- T1059.001 3 reports in ATT&CK
- T1082 3 reports reports only
- T1012 2 reports reports only
- T1071.001 2 reports reports only
- T1105 2 reports in ATT&CK
- T1112 2 reports reports only
- T1566.002 2 reports in ATT&CK
- T1573.001 2 reports reports only
- T1573.002 2 reports reports only
- T1583.001 2 reports in ATT&CK
Show all 26 techniques Show fewer
- T1583.003 2 reports in ATT&CK
- T1583.004 2 reports reports only
- T1583.008 2 reports reports only
- T1584.004 2 reports reports only
- T1027.007 1 report reports only
- T1027.013 1 report in ATT&CK
- T1055.012 1 report in ATT&CK
- T1056.001 1 report reports only
- T1057 1 report reports only
- T1071 1 report reports only
- T1125 1 report reports only
- T1204.002 1 report in ATT&CK
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1547.001 1 report reports only
- T1566 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2024-43451 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DCRat (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ave Maria (Malware Family)
-
eSentire vs. Phantom: Unveiling the Cyber Spook's Dance of Darkness
The original link failed its last check. Original publisher Detailsfor eSentire vs. Phantom: Unveiling the Cyber Spook's Dance of Darkness
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Remcos (Malware Family)
-
Imminent Monitor RAT (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Imminent Monitor RAT (Malware Family)
Show all 62 reports Show fewer
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor 奇安信威胁情报中心
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor AsyncRAT (Malware Family)
-
Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia
-
Kasablanka Group Probably Conducted Compaigns Targeting Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kasablanka Group Probably Conducted Compaigns Targeting Russia
-
BlindEagle Targeting Ecuador With Sharpened Tools
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor BlindEagle Targeting Ecuador With Sharpened Tools
-
LimeRAT Malware Is Used For Targeting Unskilled Threat Actors
The original link failed its last check. Original publisher Detailsfor LimeRAT Malware Is Used For Targeting Unskilled Threat Actors
-
Analyzing AsyncRAT distributed in Colombia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing AsyncRAT distributed in Colombia
-
APT-C-36 Updates Its Long-term Spam Campaign Against South American Entities With Commodity RATs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-36 Updates Its Long-term Spam Campaign Against South American Entities With Commodity RATs
-
APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs
-
APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs (IOCs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs (IOCs)
-
Literature lover targeting Colombia with LimeRAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Literature lover targeting Colombia with LimeRAT
-
APT-C-36 recent activity analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-36 recent activity analysis
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en
Newest first. Details opens the report in Explore.