logo

APT-C-36: Latin America’s Persistent Cyber-Espionage Force

ID: 4d121bd3-ab9f-5857-835a-b00b9e649587

STIX ID: report--4d121bd3-ab9f-5857-835a-b00b9e649587

Feed Name: Brandefense Blog

Threat Score
70/100

Date Published: 2026-02-19

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

APT-C-36 (aka Blind Eagle) is a Latin America–focused cyber-espionage actor active since 2018 that blends political intelligence collection with financially motivated theft; it primarily uses spearphishing (impersonating tax, legal, and telecom authorities), PowerShell-based loaders, and commodity RATs (AsyncRAT, QuasarRAT, njRAT, BitRAT) to gain access, persist via scheduled tasks/registry changes, and exfiltrate credentials and documents from government and financial institutions across South America. The report outlines observed campaigns from 2023–2025, OPSEC and infrastructure rotation tactics, and recommends localized user awareness, behavioral detection, network segmentation/Zero Trust, and regional intelligence sharing to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.