logo

BlindEagle Leveraging BlotchyQuasar

ID: fb30ea2c-339c-5148-9df1-f618e2721d0f

STIX ID: report--fb30ea2c-339c-5148-9df1-f618e2721d0f

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**BlindEagle campaign delivering BlotchyQuasar RAT**: The report documents a phishing campaign targeting Colombian and Ecuadorian financial and insurance sectors in which password-protected ZIPs hosted on compromised Google Drive accounts install a multi-layer obfuscated .NET BlotchyQuasar (QuasarRAT variant); it details the loader chain, Pastebin-based 3DES/BASE64 C2 retrieval, keylogging and browser/FTP credential theft capabilities, lists targeted banks, and identifies C2 domains and infrastructure patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.