APT-C-36__2023__CoreSec360_APT-C-36-BlindEagle-Amadey-botnet_10-31-2023.pdf
ID: 7b20f878-ec42-41eb-8944-3677886d0d4e
STIX ID: report--7b20f878-ec42-41eb-8944-3677886d0d4e
Threat Score
80/100
Uploaded: 2026-08-07
Published Date: 2023-12-12
Last Modified Date: 2023-12-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Threat Intelligence Center reports that APT-C-36 (Blind Eagle) has been observed using PDF spear-phishing to deliver an Amadey botnet payload alongside a reflective-loading net_dll component; the campaign employs encrypted attachments, PowerShell/VBS scripts for persistence and reflective loading, and communicates with identified C2 infrastructure (multiple URLs and IPs) to exfiltrate data and deploy plugins (cred.dll, clip.dll). The report provides technical artifacts, code excerpts, behavioral details, and actionable IOCs (file hashes, URLs, domain names) tied to targeted attacks in Colombia and neighboring countries.
