logo

APT-C-36__2023__CoreSec360_APT-C-36-BlindEagle-Amadey-botnet_10-31-2023.pdf

ID: 7b20f878-ec42-41eb-8944-3677886d0d4e

STIX ID: report--7b20f878-ec42-41eb-8944-3677886d0d4e

Threat Score

80/100

Uploaded: 2026-08-07

Published Date: 2023-12-12

Last Modified Date: 2023-12-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Threat Intelligence Center reports that APT-C-36 (Blind Eagle) has been observed using PDF spear-phishing to deliver an Amadey botnet payload alongside a reflective-loading net_dll component; the campaign employs encrypted attachments, PowerShell/VBS scripts for persistence and reflective loading, and communicates with identified C2 infrastructure (multiple URLs and IPs) to exfiltrate data and deploy plugins (cred.dll, clip.dll). The report provides technical artifacts, code excerpts, behavioral details, and actionable IOCs (file hashes, URLs, domain names) tied to targeted attacks in Colombia and neighboring countries.