News Room
16
Share
criticalCyber Espionage

APT-C-36: Latin America's Persistent Cyber Espionage Threat

APT-C-36, also known as Blind Eagle, has been targeting Latin American governments and financial institutions since 2018, employing sophisticated tactics to extract sensitive information.

₿

Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Latin America's Persistent Cyber Espionage Threat for ₿ 0.10 BTC. Contact us.

30 March 2026Last updated 30 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Critical
Actor Type:
Nation-State
Geography:
Latin America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

APT-C-36, also known as Blind Eagle, has been a persistent cyber espionage threat in Latin America since 2018. This group has primarily targeted government agencies and financial institutions, employing sophisticated tactics to extract sensitive information.

Operational Overview

APT-C-36's operations are characterized by long-term intrusions, often remaining undetected for extended periods. Their activities include spear-phishing campaigns, exploitation of zero-day vulnerabilities, and the use of custom malware to maintain access to compromised networks. The group's primary objective appears to be intelligence collection, focusing on political, economic, and strategic data.

Notable Incidents

In December 2025, Check Point Research reported a 26% year-over-year increase in cyberattacks in Latin America, with organizations experiencing an average of 3,065 attacks per week. While this surge encompasses various threat actors, APT-C-36's activities contribute significantly to the region's heightened cyber threat landscape. (blog.checkpoint.com)

Tactics, Techniques, and Procedures (TTPs)

APT-C-36 employs a range of TTPs, including:

  • Spear-Phishing: Crafting targeted emails to deceive recipients into opening malicious attachments or clicking on harmful links.

  • Exploitation of Zero-Day Vulnerabilities: Identifying and exploiting previously unknown vulnerabilities in software to gain unauthorized access.

  • Custom Malware Deployment: Utilizing bespoke malware to establish persistent access and exfiltrate data without detection.

Impact and Implications

The activities of APT-C-36 pose significant risks to the stability and security of Latin American nations. The group's focus on intelligence collection can lead to the compromise of sensitive governmental and financial data, potentially influencing political decisions and economic stability.

Recommendations

Organizations in Latin America should enhance their cybersecurity measures by:

  • Regular Security Audits: Conducting thorough assessments to identify and mitigate vulnerabilities.

  • Employee Training: Educating staff on recognizing and responding to phishing attempts and other social engineering tactics.

  • Incident Response Planning: Developing and regularly updating plans to respond effectively to cyber incidents.

Conclusion

APT-C-36 remains a formidable cyber espionage threat in Latin America. Continuous vigilance and proactive cybersecurity strategies are essential to mitigate the risks posed by this and similar threat actors.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo