APT-C-36__2023__APT_Blind_Eagles_Malware_Arsenal_Technical_Analysis_of_the_New.pdf
ID: c3b5d461-1d4d-4468-af66-0d675825769c
STIX ID: report--c3b5d461-1d4d-4468-af66-0d675825769c
Threat Score
78/100
Uploaded: 2026-08-07
Published Date: 2023-04-17
Last Modified Date: 2023-04-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT Blind Eagle (aka APT-C-36) employs a multi-stage espionage campaign: a JavaScript ActiveX downloader launches PowerShell from a Discord CDN-hosted script, subsequent PowerShell stages load AMSI-bypassing DLLs, store encrypted payloads in the registry, drop a VBScript and batch file for persistence in the Startup folder, and eventually decrypt and execute a payload that results in njRAT (Bladabindi). The report includes deobfuscated code snippets, a YARA rule, IoCs (multiple SHA256 hashes, Discord URL, DuckDNS C2), and mapped MITRE ATT&CK techniques to support detection and response.
