logo

BlindEagle Deploys Caminho and DCRAT

ID: 59236248-72df-54a9-a287-3f7af25faf1b

STIX ID: report--59236248-72df-54a9-a287-3f7af25faf1b

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-12-16

Date Updated: 2026-05-01

...
...

### Executive summary: This report analyzes a targeted phishing campaign by ‘BlindEagle’ that uses a clickable SVG to deliver obfuscated JavaScript and PowerShell which load the Caminho loader in memory and ultimately deploy the DCRAT remote-access trojan via process hollowing; the analysis includes deobfuscation methods, sample code fragments, a Discord-hosted payload URL, and a list of C2 hosts tied to the embedded certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.