APT-C-36
MITRE ATT&CK: G0099 View on attack.mitre.org
Aliases: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, APT-C-36
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- Espionage
- Related IoCs
- 73 (47 malicious)
- Last IoC activity
- 2026-09-01 20:34:33
- Profile updated
- 2026-07-07 11:56:35
Targeted industries: government-and-public-sector financial-services energy-and-utilities manufacturing professional-services
Targeted regions: country_code:co
Context
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.
Recent IoC activity
47 malicious indicators in Maltiverse are attributed to APT-C-36 (G0099). The 20 most recently updated:
Detection coverage
- 23 YARA rules
- 667 Sigma rules
Malware & tools used
- Domains (attack-pattern)
- Malicious File (attack-pattern)
- Written Content (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- JavaScript (attack-pattern)
- Impersonation (attack-pattern)
- Malware (attack-pattern)
- Botnet (attack-pattern)
- Web Services (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Tool (attack-pattern)
- Malware (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Internal Spearphishing (attack-pattern)
- Malicious Link (attack-pattern)
- Audio-Visual Content (attack-pattern)
- Email Accounts (attack-pattern)
- Scheduled Task (attack-pattern)
- Execution Guardrails (attack-pattern)
- Spearphishing Link (attack-pattern)
- External Remote Services (attack-pattern)
- Virtual Private Server (attack-pattern)
Reports & references
- ti.360.net — Apt C 36 Continuous Attacks Targeting Colombian Government Institutions And Corporations En (report)
- ecucert.gob.ec — Alerta Apts 2022 03 23 (report)
- blogs.blackberry.com — Blind Eagle Apt C 36 Targets Colombia (report)
- lab52.io — Apt C 36 Recent Activity Analysis (report)
- Trend Micro — Apt C 36 Updates Its Long Term Spam Campaign Against South Ameri (report)
- research.checkpoint.com — Blindeagle Targeting Ecuador With Sharpened Tools (report)
- MITRE ATT&CK — G0099 (report)
- assets.recordedfuture.com — Cta 2025 0826 (report)
- research.checkpoint.com — Blind Eagle And Justice For All (report)
- Kaspersky — 113414 (report)
- web.archive.org — Apt C 36 Continuous Attacks Targeting Colombian Government Institutions And Corporations En (report)
Attributed from
- Operation Spalax (campaign)
External references
- mitre-attack — G0099
- Blind Eagle
- TAG-144
- AguilaCiega
- APT-Q-98
- Check Point Blind Eagle MAR 2025
- Kaspersky BlindEagle AUG 2024
- Recorded Future TAG-144 AUG 2025
- QiAnXin APT-C-36 Feb2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy