APT-C-36: Persistent Cyber Espionage Threatens Latin American Entities
APT-C-36, also known as Blind Eagle, has been actively targeting Latin American governments and corporations since 2018, employing sophisticated cyber espionage tactics to infiltrate critical sectors.
Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Persistent Cyber Espionage Threatens Latin American Entities for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
APT-C-36, also known as Blind Eagle, has been a persistent cyber espionage threat in Latin America since 2018. This group has consistently targeted government institutions, financial entities, and critical infrastructure across the region, employing sophisticated techniques to infiltrate and exfiltrate sensitive information.
Targeted Sectors and Victims
The group's primary targets include:
-
Government Entities: Agencies responsible for national security, foreign affairs, and public administration.
-
Financial Institutions: Banks and financial services companies handling sensitive economic data.
-
Critical Infrastructure: Sectors such as energy, oil and gas, transportation, and telecommunications.
Notably, Colombia has been a focal point, with approximately 87% of observed victims located there. (thecyberexpress.com)
Tactics, Techniques, and Procedures (TTPs)
APT-C-36 employs a range of TTPs to achieve its objectives:
-
Phishing Campaigns: Crafted emails impersonating legitimate entities, such as Colombia's National Directorate of Taxes and Customs or the Ministry of Foreign Affairs, to deliver malicious payloads. (securityonline.info)
-
Malware Deployment: Utilization of remote access tools (RATs) like njRAT, Lime-RAT, and BitRAT to establish persistent access and facilitate data exfiltration. (kaspersky.com)
-
Exploitation of Vulnerabilities: Abuse of signed binaries from legitimate software products to execute malicious code, often through DLL side-loading techniques. (kaspersky.com)
Recent Developments
In early 2026, Kaspersky's Global Research and Analysis Team (GReAT) identified a new spy plugin used by APT-C-36. This plugin, delivered via ZIP files containing executable files, initiates infection through sideloading and includes various malicious components to facilitate the attack chain. (kaspersky.com)
Implications and Recommendations
The persistent activities of APT-C-36 underscore the critical need for enhanced cybersecurity measures within Latin American organizations. To mitigate the risks associated with such advanced persistent threats, the following actions are recommended:
-
Employee Training: Regularly educate staff on recognizing phishing attempts and the importance of cautious email interactions.
-
System Hardening: Ensure all systems are updated with the latest security patches to close known vulnerabilities.
-
Network Monitoring: Implement continuous monitoring to detect unusual activities indicative of unauthorized access.
-
Incident Response Planning: Develop and regularly update incident response plans to ensure swift and effective reactions to potential breaches.
By adopting a proactive and comprehensive cybersecurity strategy, organizations can better defend against the evolving tactics of APT-C-36 and similar threat actors.
Highlights:
- APT-C-36: Latin America’s Persistent Cyber-Espionage Force - Brandefense, Published on Wednesday, February 18
- BlindEagle APT Group: A Persistent Threat In Latin America, Published on Monday, August 19
- Kaspersky identifies BlindEagle’s new spy plugin, Published on Sunday, August 18
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



