ATT&CKReferencesLevelBlue Blind Eagle Proton66 JUN 2025

LevelBlue Blind Eagle Proton66 JUN 2025

Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1584.005
Botnet
GroupAPT-C-36

APT-C-36 has used a botnet management interface to control large numbers of compromised hosts.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1593
Search Open Websites/Domains
GroupAPT-C-36

APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1683.002
Audio-Visual Content
GroupAPT-C-36

APT-C-36 has used phishing pages appearing like legitimate banking login portals to compromise credentials.

T1684.001
Impersonation
GroupAPT-C-36

APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.