News Room
16
Share
mediumCyber Espionage

APT-C-36: Latin America's Persistent Cyber Espionage Threat

APT-C-36, also known as Blind Eagle, has been actively targeting Latin American governments and organizations since 2018, employing sophisticated cyber espionage tactics to infiltrate critical sectors.

₿

Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Latin America's Persistent Cyber Espionage Threat for ₿ 0.10 BTC. Contact us.

28 March 2026Last updated 28 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
APT
Geography:
Latin America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Overview of APT-C-36

APT-C-36, also referred to as Blind Eagle, Blind Spider, and TAG-144, is a cyber espionage group that has been active in Latin America since approximately 2018. The group primarily targets government ministries, financial institutions, telecommunications providers, and educational institutions across South America. Their operations are characterized by a hybrid approach that combines intelligence collection with financial motives, often exploiting local socio-political contexts to enhance the effectiveness of their campaigns.

Tactics, Techniques, and Procedures (TTPs)

APT-C-36 employs a range of tactics to gain initial access and maintain persistence within victim networks:

  • Spear Phishing: The group frequently uses spear-phishing emails that impersonate government tax notifications or legal documents. These emails often contain malicious attachments or links leading to counterfeit credential-harvesting sites.

  • Living-off-the-Land (LotL) Techniques: To evade detection, APT-C-36 utilizes existing system tools and processes. They have been observed using PowerShell-based scripts to download and execute payloads, and they often abuse legitimate remote administration tools (RATs) such as AsyncRAT, QuasarRAT, and BitRAT for command and control (C2) communications.

  • Persistence Mechanisms: Once inside a network, the group establishes persistence through scheduled tasks, registry modifications, and by leveraging legitimate remote administration tools. This approach allows them to maintain long-term access without triggering security alerts.

Notable Operations

Over the years, APT-C-36 has conducted several significant operations:

  • 2023 – Tax Authority Phishing Campaign: The group impersonated Colombia's Dirección de Impuestos y Aduanas Nacionales (DIAN) to send phishing emails with malicious PDF attachments. These attachments deployed AsyncRAT to extract credentials from government employees.

  • 2024 – Financial Institution Breach: APT-C-36 targeted banking networks in South America using fake legal notifications as lures. Compromised credentials enabled lateral movement within internal banking systems, leading to data exfiltration.

  • 2025 – Public Sector Espionage Campaign: Intelligence suggests that APT-C-36 conducted spear-phishing campaigns within Colombian ministries, utilizing PowerShell loaders and encrypted C2 channels to maintain a stealthy and sustainable presence.

Recent Developments and Evolution

Recent intelligence indicates that APT-C-36 continues to evolve its tactics:

  • Infrastructure Rotation: The group frequently registers new domains and sets up temporary servers to avoid blacklisting, enhancing the longevity of their operations.

  • Enhanced Encryption: They have adopted HTTPS and cloud-based C2 communications to obfuscate their activities and blend malicious traffic with legitimate network communications.

  • Tool Diversification: APT-C-36 increasingly uses commodity malware and publicly available tools, reducing the need for custom malware development and lowering the risk of detection.

Strategic Impact and Defensive Recommendations

APT-C-36 exemplifies the growing sophistication of regional APTs that blend espionage with financial motives. Their operations highlight the need for localized defense strategies:

  • Localized Awareness Campaigns: Organizations in Latin America should develop awareness training focused on local phishing techniques and social engineering tactics.

  • Behavioral Detection: Implement behavioral-based detection methods to identify unusual PowerShell executions and signs of C2 communications, rather than relying solely on signature-based security measures.

  • Network Segmentation and Zero Trust Models: Employ network segmentation to limit lateral movement and adopt Zero Trust architectures to monitor user activity and privilege escalation.

  • Regional Intelligence Sharing: Collaborate with regional Computer Emergency Response Teams (CERTs) and private sector organizations to disrupt APT-C-36's infrastructure and identify overlaps quickly.

Conclusion

APT-C-36 represents a significant cyber threat within Latin America, demonstrating the capabilities of regional actors to conduct sustained and sophisticated cyber espionage campaigns. Their operations underscore the importance of tailored defense strategies and regional cooperation to mitigate such threats effectively.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo