logo

APT_Blind_Eagles.pdf

ID: 1a616b35-667e-49d3-9034-392dd45e0394

STIX ID: report--1a616b35-667e-49d3-9034-392dd45e0394

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2019-02-19

Last Modified Date: 2019-02-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This 360 Threat Intelligence report documents a sustained APT campaign (named 盲眼鹰 / APT-C-36) from April 2018 targeting Colombian government agencies and major companies via spear-phishing: attackers mailed RAR-encrypted MHTML Word lures with malicious macros that dropped the Imminent Monitor RAT (multiple samples), established C2 (e.g. mentes.publicvm.com:4050 / 128.90.107.88), and used VPNs and domain impersonation; the report provides detailed technical analysis, TTPs, IOCs (file hashes, domains, URLs, encrypted RAR passwords), victim list, timeline, and attribution indicators suggesting a South American (UTC-4) actor.