APT-C-36: Latin America's Persistent Cyber Espionage Threat
APT-C-36, also known as Blind Eagle, has been targeting Latin American governments and financial institutions since 2018, employing sophisticated tactics to extract sensitive information.
Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Latin America's Persistent Cyber Espionage Threat for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
APT-C-36, also known as Blind Eagle, has been a persistent cyber espionage threat in Latin America since 2018. This group has primarily targeted government agencies and financial institutions, employing sophisticated tactics to extract sensitive information.
Operational Overview
APT-C-36's operations are characterized by long-term intrusions, often remaining undetected for extended periods. Their activities include spear-phishing campaigns, exploitation of zero-day vulnerabilities, and the use of custom malware to maintain access to compromised networks. The group's primary objective appears to be intelligence collection, focusing on political, economic, and strategic data.
Notable Incidents
In December 2025, Check Point Research reported a 26% year-over-year increase in cyberattacks in Latin America, with organizations experiencing an average of 3,065 attacks per week. While this surge encompasses various threat actors, APT-C-36's activities contribute significantly to the region's heightened cyber threat landscape. (blog.checkpoint.com)
Tactics, Techniques, and Procedures (TTPs)
APT-C-36 employs a range of TTPs, including:
-
Spear-Phishing: Crafting targeted emails to deceive recipients into opening malicious attachments or clicking on harmful links.
-
Exploitation of Zero-Day Vulnerabilities: Identifying and exploiting previously unknown vulnerabilities in software to gain unauthorized access.
-
Custom Malware Deployment: Utilizing bespoke malware to establish persistent access and exfiltrate data without detection.
Impact and Implications
The activities of APT-C-36 pose significant risks to the stability and security of Latin American nations. The group's focus on intelligence collection can lead to the compromise of sensitive governmental and financial data, potentially influencing political decisions and economic stability.
Recommendations
Organizations in Latin America should enhance their cybersecurity measures by:
-
Regular Security Audits: Conducting thorough assessments to identify and mitigate vulnerabilities.
-
Employee Training: Educating staff on recognizing and responding to phishing attempts and other social engineering tactics.
-
Incident Response Planning: Developing and regularly updating plans to respond effectively to cyber incidents.
Conclusion
APT-C-36 remains a formidable cyber espionage threat in Latin America. Continuous vigilance and proactive cybersecurity strategies are essential to mitigate the risks posed by this and similar threat actors.
Highlights:
- Cyber Attacks Surge in Latin America | Dec 2025, Published on Monday, January 12
- Surging Cyberattacks Boost Latin America to Riskiest Region, Published on Tuesday, January 27
- LatAm Now Faces 2x More Cyberattacks Than the US, Published on Wednesday, March 04
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Russian State-Nexus Cluster GTG-20006 Weaponizes AI for Automated Espionage Operations

China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure

