APT-C-36: Latin America’s Persistent Cyber-Espionage Force
ID: 4d121bd3-ab9f-5857-835a-b00b9e649587
STIX ID: report--4d121bd3-ab9f-5857-835a-b00b9e649587
Feed Name: Brandefense Blog
APT-C-36 (aka Blind Eagle) is a Latin America–focused cyber-espionage actor active since 2018 that blends political intelligence collection with financially motivated theft; it primarily uses spearphishing (impersonating tax, legal, and telecom authorities), PowerShell-based loaders, and commodity RATs (AsyncRAT, QuasarRAT, njRAT, BitRAT) to gain access, persist via scheduled tasks/registry changes, and exfiltrate credentials and documents from government and financial institutions across South America. The report outlines observed campaigns from 2023–2025, OPSEC and infrastructure rotation tactics, and recommends localized user awareness, behavioral detection, network segmentation/Zero Trust, and regional intelligence sharing to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
