ATT&CKGroupsAPT-C-36

APT-C-36

G0099

Threat group.View on attack.mitre.org

About this group

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.

Techniques used38

Procedure examples38

TechniqueProcedure example
T1027
Obfuscated Files or Information

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027.003
Steganography

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.013
Encrypted/Encoded File

APT-C-36 has used encoded and obfuscated files, images, and executables.

T1027.016
Junk Code Insertion

APT-C-36 has used junk characters to obfuscate malicious scripts.

T1036.004
Masquerade Task or Service

APT-C-36 has disguised its scheduled tasks as those used by Google.

T1036.005
Match Legitimate Resource Name or Location

APT-C-36 has disguised malicious executables to appear as legitimate files.

T1047
Windows Management Instrumentation

APT-C-36 has used WMI to execute PowerShell.

T1053.005
Scheduled Task

APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.

T1055.012
Process Hollowing

APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes.

T1059.001
PowerShell

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.005
Visual Basic

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1059.007
JavaScript

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

T1105
Ingress Tool Transfer

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

T1133
External Remote Services

APT-C-36 has used VPNs in their operational infrastructure.

T1204.001
Malicious Link

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

View all 38 procedure examples

Software9

Campaigns0

None recorded.

References4

  1. Check Point Blind Eagle MAR 2025 Open source
    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.
  2. Kaspersky BlindEagle AUG 2024 Open source
    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.
  3. QiAnXin APT-C-36 Feb2019 Open source
    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.
  4. Recorded Future TAG-144 AUG 2025 Open source
    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.