
APT-C-36: Persistent Cyber Espionage Threatens Latin American Infrastructure
APT-C-36, also known as Blind Eagle, continues to target Latin American governments and critical sectors, employing sophisticated phishing and remote access tools to exfiltrate sensitive data.
Encrygma is selling the entire Full Cyber Weapon Research of APT-C-36: Persistent Cyber Espionage Threatens Latin American Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Latin America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
APT-C-36, also known as Blind Eagle, remains a significant cyber espionage threat in Latin America. Active since 2018, this group has consistently targeted government entities, financial institutions, telecommunications providers, and educational organizations across the region. Their operations blend intelligence collection with financial motives, utilizing a range of tactics, techniques, and procedures (TTPs) to infiltrate and persist within victim networks.
Operational Overview
Originating from Colombia, APT-C-36 employs a hybrid approach combining espionage and financial gain. Their primary targets include government ministries, financial services, telecommunications providers, and educational institutions. Phishing remains their signature methodology, often impersonating tax authorities, law enforcement, or telecommunications companies to entice victims into executing malicious payloads. Recent activities indicate a shift towards living-off-the-land techniques and the use of commercially available remote access tools (RATs) such as AsyncRAT, QuasarRAT, and BitRAT.
Tactics, Techniques, and Procedures (TTPs)
-
Initial Access: Spear-phishing emails posing as government tax notifications or legal documents, containing malicious attachments or links leading to counterfeit credential-harvesting sites.
-
Execution and Persistence: Upon victim interaction, PowerShell-based scripts download second-stage payloads. Persistence is achieved through scheduled tasks, registry modifications, and abuse of legitimate remote administration tools.
-
Command and Control (C2): Utilization of HTTPS-based communications, VPNs, and dynamic DNS services to obfuscate infrastructure. Cloud services and remote administration tools are employed to blend malicious activity with normal network traffic.
-
Malware and Tools: A combination of open-source and commodity RATs—AsyncRAT, QuasarRAT, njRAT, and BitRAT—along with custom droppers designed to evade local antivirus solutions. These tools facilitate remote access, credential theft, and document exfiltration.
Notable Operations
In 2023, APT-C-36 conducted a phishing campaign impersonating Colombia's DIAN (Dirección de Impuestos y Aduanas Nacionales), sending emails with malicious PDF attachments to recipients. The group has also demonstrated operational security improvements, such as frequent infrastructure rotation, encryption via HTTPS and cloud-based C2 communications, and tool diversification to reduce traceability and development costs.
Strategic Impact and Defensive Recommendations
APT-C-36 exemplifies the growing sophistication of regionally driven APTs that straddle the line between espionage and financially motivated activity. Their success underscores the need for robust cybersecurity measures tailored to the local context.
Defensive Recommendations:
-
Localized Awareness Campaigns: Organizations in Latin America should develop and support awareness training focused on local phishing techniques, particularly those involving government impersonation.
-
Behavioral Detection Over Signature-Based Security: To detect commodity malware, focus on behavioral indicators such as abnormal PowerShell execution or signs of command and control connections.
-
Network Segmentation and Zero Trust Models: Implement network segmentation to limit lateral movement and adopt Zero Trust models to monitor user activity and privilege escalation.
Conclusion
APT-C-36's persistent and evolving tactics highlight the critical need for enhanced cybersecurity measures in Latin America. By understanding and mitigating the group's TTPs, organizations can better defend against current and future cyber espionage threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



