logo

APT-C-36__2023__Checkpoint_BlindEagle-Targeting-Ecuador-Sharpened-Tools_01-05-2023.pdf

ID: 5b50786a-f06f-47e8-91f6-049fddcdfe82

STIX ID: report--5b50786a-f06f-47e8-91f6-049fddcdfe82

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2023-03-13

Last Modified Date: 2023-03-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point research documents active campaigns by Blind Eagle (APT-C-36) targeting Ecuador and Colombia using phishing that delivers multi-stage infection chains: LHA/RAR archives, PyInstaller Windows executables, mshta/VBS/PowerShell stages, and payloads including a modified .NET QuasarRAT (bank-targeting features) and a Python-based Meterpreter. The report details TTPs (geofencing via link shorteners, AV evasion, in-memory Meterpreter), targeted banking-related strings and functions, IoCs (hashes, domains, MediaFire links, shortened URLs), and concludes the financially motivated group has been evolving toward more elaborate techniques.