ATT&CKReferencesZscaler BlindEagle DEC 2025

Zscaler BlindEagle DEC 2025

Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareCaminho

Caminho can use junk code for obfuscation.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.013
Encrypted/Encoded File
ToolDCRAT

The DCRAT configuration file is encrypted using AES-256.

T1027.013
Encrypted/Encoded File
MalwareCaminho

Caminho can use code flattening for payload obfuscation.

T1047
Windows Management Instrumentation
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

T1055.012
Process Hollowing
MalwareCaminho

Caminho has launched and hollowed out MSBuild.exe to host malicious code.

T1056.001
Keylogging
ToolDCRAT

DCRAT can log keystrokes on targeted systems.

T1059.001
PowerShell
GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.007
JavaScript
GroupAPT-C-36

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

T1105
Ingress Tool Transfer
MalwareCaminho

Caminho has the ability to download files onto compromised hosts.

T1106
Native API
MalwareCaminho

Caminho can use `System.Net.WebClient.downloadString()` for file download.

T1140
Deobfuscate/Decode Files or Information
MalwareCaminho

Caminho can deobfuscate downloaded files prior to execution.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1534
Internal Spearphishing
GroupAPT-C-36

APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization.

T1564.003
Hidden Window
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1573.002
Asymmetric Cryptography
ToolDCRAT

DCRAT can use certificate-based authentication for C2 servers.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1586.002
Email Accounts
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

T1684.001
Impersonation
GroupAPT-C-36

APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General.

T1685
Disable or Modify Tools
ToolDCRAT

DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.