Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1584.005 Botnet |
GroupAPT-C-36 | APT-C-36 has used a botnet management interface to control large numbers of compromised hosts. |
| T1588.001 Malware |
GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| T1593 Search Open Websites/Domains |
GroupAPT-C-36 | APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages. |
| T1608.001 Upload Malware |
GroupAPT-C-36 | APT-C-36 has staged malware implants on group-owned repositories and sites. |
| T1683.002 Audio-Visual Content |
GroupAPT-C-36 | APT-C-36 has used phishing pages appearing like legitimate banking login portals to compromise credentials. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.