News Room
16
Share
APT-C-36: Persistent Cyber Espionage Threatens Latin American Infrastructure
highCyber Espionage

APT-C-36: Persistent Cyber Espionage Threatens Latin American Infrastructure

APT-C-36, also known as Blind Eagle, continues to target Latin American governments and critical sectors, employing sophisticated phishing and remote access tools to exfiltrate sensitive data.

₿

Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Persistent Cyber Espionage Threatens Latin American Infrastructure for ₿ 0.10 BTC. Contact us.

11 April 2026Last updated 20 August 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Latin America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

APT-C-36, also known as Blind Eagle, remains a significant cyber espionage threat in Latin America. Active since 2018, this group has consistently targeted government entities, financial institutions, telecommunications providers, and educational organizations across the region. Their operations blend intelligence collection with financial motives, utilizing a range of tactics, techniques, and procedures (TTPs) to infiltrate and persist within victim networks.

Operational Overview

Originating from Colombia, APT-C-36 employs a hybrid approach combining espionage and financial gain. Their primary targets include government ministries, financial services, telecommunications providers, and educational institutions. Phishing remains their signature methodology, often impersonating tax authorities, law enforcement, or telecommunications companies to entice victims into executing malicious payloads. Recent activities indicate a shift towards living-off-the-land techniques and the use of commercially available remote access tools (RATs) such as AsyncRAT, QuasarRAT, and BitRAT.

Tactics, Techniques, and Procedures (TTPs)

  • Initial Access: Spear-phishing emails posing as government tax notifications or legal documents, containing malicious attachments or links leading to counterfeit credential-harvesting sites.

  • Execution and Persistence: Upon victim interaction, PowerShell-based scripts download second-stage payloads. Persistence is achieved through scheduled tasks, registry modifications, and abuse of legitimate remote administration tools.

  • Command and Control (C2): Utilization of HTTPS-based communications, VPNs, and dynamic DNS services to obfuscate infrastructure. Cloud services and remote administration tools are employed to blend malicious activity with normal network traffic.

  • Malware and Tools: A combination of open-source and commodity RATs—AsyncRAT, QuasarRAT, njRAT, and BitRAT—along with custom droppers designed to evade local antivirus solutions. These tools facilitate remote access, credential theft, and document exfiltration.

Notable Operations

In 2023, APT-C-36 conducted a phishing campaign impersonating Colombia's DIAN (Dirección de Impuestos y Aduanas Nacionales), sending emails with malicious PDF attachments to recipients. The group has also demonstrated operational security improvements, such as frequent infrastructure rotation, encryption via HTTPS and cloud-based C2 communications, and tool diversification to reduce traceability and development costs.

Strategic Impact and Defensive Recommendations

APT-C-36 exemplifies the growing sophistication of regionally driven APTs that straddle the line between espionage and financially motivated activity. Their success underscores the need for robust cybersecurity measures tailored to the local context.

Defensive Recommendations:

  1. Localized Awareness Campaigns: Organizations in Latin America should develop and support awareness training focused on local phishing techniques, particularly those involving government impersonation.

  2. Behavioral Detection Over Signature-Based Security: To detect commodity malware, focus on behavioral indicators such as abnormal PowerShell execution or signs of command and control connections.

  3. Network Segmentation and Zero Trust Models: Implement network segmentation to limit lateral movement and adopt Zero Trust models to monitor user activity and privilege escalation.

Conclusion

APT-C-36's persistent and evolving tactics highlight the critical need for enhanced cybersecurity measures in Latin America. By understanding and mitigating the group's TTPs, organizations can better defend against current and future cyber espionage threats.

(brandefense.io)

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo