APT-C-36

MITRE ATT&CK: G0099 View on attack.mitre.org

Aliases: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, APT-C-36

First seen
2018-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
Espionage
Related IoCs
73 (47 malicious)
Last IoC activity
2026-09-01 20:34:33
Profile updated
2026-07-07 11:56:35

Targeted industries: government-and-public-sector financial-services energy-and-utilities manufacturing professional-services

Targeted regions: country_code:co

Context

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.

Recent IoC activity

47 malicious indicators in Maltiverse are attributed to APT-C-36 (G0099). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname envio2121.duckdns.org 2026-09-03 2
hostname ceoseguros.com 2026-09-02 3
hostname smbc-support.duckdns.org 2026-09-02 2
hostname www.w-verify.duckdns.org 2026-09-02 2
hostname w-verify.duckdns.org 2026-09-02 2
file sample 7be351516e7b50445ee35253b34d1b7d655d2e12ef5badfdbdc376197c5ca741 2026-08-26 1
hostname dianportalcomco.com 2026-08-25 2
hostname ceosas.linkpc.net 2026-08-16 3
URL http://ceoseguros.com/css/c.jpg 2026-08-08 1
hostname ceoempresarialsas.com 2026-08-08 1
URL https://192.169.69.26/ 2026-07-24 2
URL http://ismaboli.com/js/i.jpg 2026-07-16 1
hostname medicosco.publicvm.com 2026-07-15 2
hostname mentes.publicvm.com 2026-07-15 2
URL https://152.200.146.245/ 2026-07-15 2
URL http://ismaboli.com/dir/i.jpg 2026-07-15 1
URL http://192.169.69.26:8080/ 2026-07-14 2
file sample 03b0e67b65740307c5f7109587ff3218aa803c0998a23f83f8790fd9a1e0fb47 2026-07-14 1
URL http://dianmuiscaingreso.com/css/w.jpg 2026-07-14 1
URL http://192.169.69.26/ 2026-07-13 2

Detection coverage

  • 23 YARA rules
  • 667 Sigma rules

Malware & tools used

  • Domains (attack-pattern)
  • Malicious File (attack-pattern)
  • Written Content (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • JavaScript (attack-pattern)
  • Impersonation (attack-pattern)
  • Malware (attack-pattern)
  • Botnet (attack-pattern)
  • Web Services (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Tool (attack-pattern)
  • Malware (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Internal Spearphishing (attack-pattern)
  • Malicious Link (attack-pattern)
  • Audio-Visual Content (attack-pattern)
  • Email Accounts (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • External Remote Services (attack-pattern)
  • Virtual Private Server (attack-pattern)

Reports & references

  • ti.360.net — Apt C 36 Continuous Attacks Targeting Colombian Government Institutions And Corporations En (report)
  • ecucert.gob.ec — Alerta Apts 2022 03 23 (report)
  • blogs.blackberry.com — Blind Eagle Apt C 36 Targets Colombia (report)
  • lab52.io — Apt C 36 Recent Activity Analysis (report)
  • Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
  • research.checkpoint.com — Blindeagle Targeting Ecuador With Sharpened Tools (report)
  • MITRE ATT&CK — G0099 (report)
  • assets.recordedfuture.com — Cta 2025 0826 (report)
  • research.checkpoint.com — Blind Eagle And Justice For All (report)
  • Kaspersky — 113414 (report)
  • web.archive.org — Apt C 36 Continuous Attacks Targeting Colombian Government Institutions And Corporations En (report)

Attributed from

  • Operation Spalax (campaign)

External references