logo

Dark Web Profile: BlindEagle

ID: 7e28615d-7493-5409-8e53-a2b578b25a59

STIX ID: report--7e28615d-7493-5409-8e53-a2b578b25a59

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Ameer Owda

...
...

BlindEagle (APT‑C‑36) is a South American–based hybrid espionage and cybercrime actor active since 2018 that uses culturally tailored, geofenced spear-phishing and commodity RATs (AsyncRAT, Remcos, njRAT, Quasar variants, DCRAT, etc.) to target Colombian government, judiciary, and regional banks; the report documents multi-stage droppers, process hollowing, rotating loaders/crypters, observed C2 and hosting infrastructure, and an exposed HTML containing thousands of stolen PII entries, indicating persistent region-focused operations with significant operational discipline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.