Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.016 Junk Code Insertion |
GroupAPT-C-36 | APT-C-36 has used junk characters to obfuscate malicious scripts. |
| T1133 External Remote Services |
GroupAPT-C-36 | APT-C-36 has used VPNs in their operational infrastructure. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1204.002 Malicious File |
ToolAsyncRAT | AsyncRAT has been executed through victims opening malicious file attachments. |
| T1480 Execution Guardrails |
GroupAPT-C-36 | APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites. |
| T1566.001 Spearphishing Attachment |
ToolAsyncRAT | AsyncRAT has been delivered via malicious email attachments. |
| T1566.001 Spearphishing Attachment |
GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| T1566.002 Spearphishing Link |
GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.003 Virtual Private Server |
GroupAPT-C-36 | APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1586.002 Email Accounts |
GroupAPT-C-36 | APT-C-36 has regularly used compromised email accounts in spearphishing campaigns. |
| T1586.003 Cloud Accounts |
GroupAPT-C-36 | APT-C-36 has used compromised Google Drive accounts including one associated with a Colombian government organization. |
| T1588.001 Malware |
GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.