APT_Blind_Eagles.pdf
ID: 1a616b35-667e-49d3-9034-392dd45e0394
STIX ID: report--1a616b35-667e-49d3-9034-392dd45e0394
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2019-02-19
Last Modified Date: 2019-02-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This 360 Threat Intelligence report documents a sustained APT campaign (named 盲眼鹰 / APT-C-36) from April 2018 targeting Colombian government agencies and major companies via spear-phishing: attackers mailed RAR-encrypted MHTML Word lures with malicious macros that dropped the Imminent Monitor RAT (multiple samples), established C2 (e.g. mentes.publicvm.com:4050 / 128.90.107.88), and used VPNs and domain impersonation; the report provides detailed technical analysis, TTPs, IOCs (file hashes, domains, URLs, encrypted RAR passwords), victim list, timeline, and attribution indicators suggesting a South American (UTC-4) actor.
