logo

BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls

ID: 55de8330-1c4d-5d59-a40e-fbf9dad57ba1

STIX ID: report--55de8330-1c4d-5d59-a40e-fbf9dad57ba1

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

BlindEagle targeted a Colombian government institution by compromising an internal email account to send phishing messages with an SVG attachment that redirects victims to a fake portal. The portal delivers obfuscated JavaScript that triggers a fileless infection: scripts deobfuscate payloads, a PowerShell command retrieves a PNG from the Internet Archive containing the Caminho downloader, which pulls a text payload from a Discord CDN and decodes it in memory before injecting the DCRAT RAT into a hollowed MSBuild.exe process, enabling keylogging and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.