logo

APT-C-36__2019__apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en.pdf

ID: bbd1d92e-a22f-40c6-a84b-9e4fe50e67e3

STIX ID: report--bbd1d92e-a22f-40c6-a84b-9e4fe50e67e3

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2019-02-19

Last Modified Date: 2019-02-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT‑C‑36 (aka Blind Eagle) ran a targeted spear‑phishing campaign since April 2018 against Colombian government institutions and major corporations by sending password‑protected RARs containing MHTML macro documents that drop and persist a .NET Imminent Monitor RAT. The report details the infection chain (encrypted RAR → MHTML macro → downloader → 1.exe → Imminent payload), C2 infrastructure (mentes.publicvm.com and others), extensive IOCs (MD5s, domains, IPs), victim list, and assessed attacker provenance (Spanish locale, UTC‑4), plus recommended detection artefacts and TTP mapping.