logo

APT-C-36__2023__APT_Blind_Eagles_Malware_Arsenal_Technical_Analysis_of_the_New.pdf

ID: c3b5d461-1d4d-4468-af66-0d675825769c

STIX ID: report--c3b5d461-1d4d-4468-af66-0d675825769c

Threat Score

78/100

Uploaded: 2026-08-07

Published Date: 2023-04-17

Last Modified Date: 2023-04-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT Blind Eagle (aka APT-C-36) employs a multi-stage espionage campaign: a JavaScript ActiveX downloader launches PowerShell from a Discord CDN-hosted script, subsequent PowerShell stages load AMSI-bypassing DLLs, store encrypted payloads in the registry, drop a VBScript and batch file for persistence in the Startup folder, and eventually decrypt and execute a payload that results in njRAT (Bladabindi). The report includes deobfuscated code snippets, a YARA rule, IoCs (multiple SHA256 hashes, Discord URL, DuckDNS C2), and mapped MITRE ATT&CK techniques to support detection and response.