APT-C-36__2023__Blackberry_BlindEagle-Fake-UUE-Fsociety-Target-Colombia_02-27-2023.pdf
ID: 34cfc5c6-310e-400a-a42c-2821b8a955a1
STIX ID: report--34cfc5c6-310e-400a-a42c-2821b8a955a1
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2023-03-01
Last Modified Date: 2023-03-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT-C-36 (Blind Eagle) ran targeted spear-phishing campaigns against Colombian (and regional) government, judiciary, financial, health and law-enforcement entities using malicious PDF lures that lead victims to download UUE/RAR archives containing VBS. The VBS decodes and runs PowerShell to fetch and load .NET DLLs (Fiber.dll, Fsociety.dll) in memory, which in turn deploy AsyncRAT (loaded into RegSvcs.exe via process hollowing); persistence is achieved via scheduled tasks or HKCU Run entries and C2 is observed at asy1543.duckdns.org:1543 and several associated IPs, with numerous file and network IOCs provided.
