ATT&CKReferencesRecorded Future TAG-144 AUG 2025

Recorded Future TAG-144 AUG 2025

Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.016
Junk Code Insertion
GroupAPT-C-36

APT-C-36 has used junk characters to obfuscate malicious scripts.

T1133
External Remote Services
GroupAPT-C-36

APT-C-36 has used VPNs in their operational infrastructure.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1204.002
Malicious File
ToolAsyncRAT

AsyncRAT has been executed through victims opening malicious file attachments.

T1480
Execution Guardrails
GroupAPT-C-36

APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites.

T1566.001
Spearphishing Attachment
ToolAsyncRAT

AsyncRAT has been delivered via malicious email attachments.

T1566.001
Spearphishing Attachment
GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

T1566.002
Spearphishing Link
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.003
Virtual Private Server
GroupAPT-C-36

APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1586.002
Email Accounts
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

T1586.003
Cloud Accounts
GroupAPT-C-36

APT-C-36 has used compromised Google Drive accounts including one associated with a Colombian government organization.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1684.001
Impersonation
GroupAPT-C-36

APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.