APT-C-36

APT / StateG0099
Techniques (MITRE ATT&CK)38
SourceMITRE ATT&CK
Target categories: Petroleum, Manufacturing, Financial, Private sector, Government
Targeted regions: Ecuador · Colombia · Spain · Panama · Chile
Also known as:APT-Q-98AguilaCiegaBlind EagleTAG-144

Vexday analysis

Grupo de ameaça persistente avançada de origem sul-americana, o APT-C-36 — também rastreado como Blind Eagle, TAG-144, AguilaCiega e APT-Q-98 (identificador MITRE ATT&CK: G0099) — conduz operações de espionagem e motivadas financeiramente ao menos desde 2018. Suas atividades têm como alvo instituições governamentais e entidades dos setores financeiro, energético e de manufatura na Colômbia e em outros países da América Latina. Ao grupo são atribuídas 38 técnicas documentadas na base MITRE ATT&CK.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity39
Impact: High
T1566.001T1047T1133ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceExternal RemoteServicesLATLateral movementInternalSpearphishing

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 748

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

urlhttp://dsfdsfs.xsph.ru/L1nc0In.phpDCRatthreatfox
sha256_hash24fdc48249a04de295cbcc222a9da62ecffdf60cee25c3879bf12ccab3393282DCRatmalwarebazaar
urlhttp://ce557109.tw1.ru/L1nc0In.phpDCRatthreatfox
ip:port2.56.165.157:991NjRATthreatfox
ip:port91.202.233.120:8848DCRatthreatfox
ip:port103.83.87.87:27900Remcosthreatfox
ip:port103.83.87.87:26900Remcosthreatfox
ip:port103.83.87.87:24900Remcosthreatfox
ip:port103.83.87.87:22300Remcosthreatfox
domainwhichkindwahalabethisonesooluwahelurboi.duckdns.orgRemcosthreatfox
ip:port155.103.69.20:14647Remcosthreatfox
domaineventras.duckdns.orgRemcosthreatfox
ip:port107.175.88.92:2404Remcosthreatfox
ip:port45.74.3.160:2404Remcosthreatfox
ip:port87.120.244.219:13131Remcosthreatfox
ip:port185.91.126.112:443Remcosthreatfox
ip:port77.110.108.14:9001Remcosthreatfox
ip:port80.97.160.237:23401Remcosthreatfox
ip:port91.193.7.162:13309Remcosthreatfox
ip:port144.24.14.113:7005Remcosthreatfox
ip:port185.116.238.123:8088Remcosthreatfox
ip:port104.251.181.148:1427Remcosthreatfox
ip:port15.204.115.143:2404Remcosthreatfox
ip:port104.251.181.148:443Remcosthreatfox
ip:port104.251.181.148:80Remcosthreatfox
ip:port185.91.126.107:443Remcosthreatfox
domainxoso6640.comRemcosthreatfox
domainaseguradora2026.kozow.comRemcosthreatfox
domain2301amarilloa.kozow.comRemcosthreatfox
domainnordking.spaceRemcosthreatfox

+748 indicators in total. See them all on the IOCs page.

APT-C-36 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →