Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APT-C-36

Also known as: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, APT-C-36, South America

Description

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.(Citation: QiAnXin APT-C-36 Feb2019)(Citation: Kaspersky BlindEagle AUG 2024)(Citation: Check Point Blind Eagle MAR 2025)(Citation: Recorded Future TAG-144 AUG 2025)

Goals & Targeting

Targeted Sectors

Government
Manufacturing
Financial services

Targeted Countries / Regions

Colombia

AI Analysis

· 2 months ago

Executive Summary

APT-C-36 is a suspected South American threat group engaged in espionage and financially motivated operations, targeting government institutions and entities in the financial, energy, and manufacturing sectors. The group's primary motivation is espionage, and its activities have been linked to the South American region. APT-C-36's capabilities and motivations suggest a high level of sophistication, with the ability to adapt and evolve its TTPs to evade detection and achieve its objectives.

Enhanced Description

APT-C-36, also known as Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, and APT-C-36, is a suspected South American threat group that has been engaged in espionage and financially motivated operations since at least 2018. The group's primary motivation is espionage, and it has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries. APT-C-36's operations have been documented by multiple security firms, including QiAnXin, Kaspersky, Check Point, and Recorded Future, providing valuable insights into the group's tactics, techniques, and procedures (TTPs). The group's activities have been consistently linked to the South American region, with a focus on targeting critical infrastructure and sensitive information. APT-C-36's capabilities and motivations suggest a high level of sophistication, with the ability to adapt and evolve its TTPs to evade detection and achieve its objectives. The group's use of various aliases and its ability to operate undetected for extended periods highlight the importance of continuous monitoring and threat intelligence gathering to stay ahead of this threat. APT-C-36's TTPs are likely to continue evolving, making it essential for organizations to remain vigilant and implement robust defensive measures to protect against this threat. The threat actor's activities have significant implications for organizations operating in the government, manufacturing, and financial services sectors, particularly in Colombia and other Latin American countries.

Key Capabilities

  • Initial Access
  • Network Exploitation
  • Credential Harvesting
  • Data Exfiltration
  • Evasion and Obfuscation
  • Social Engineering

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

Recommended Actions

  • Implement robust network monitoring and intrusion detection systems
  • Conduct regular security audits and vulnerability assessments
  • Enforce strong password policies and multi-factor authentication
  • Provide regular security awareness training for employees
  • Implement a defense-in-depth approach to protect against multiple attack vectors

Suggested Tags

APT
Espionage
Financially Motivated
South America
Government
Manufacturing
Financial Services

Confidence Assessment

The confidence level in the available data is moderate, with multiple security firms providing insights into APT-C-36's TTPs. However, there are information gaps regarding the group's exact sophistication level, motivations, and affiliations, which could impact the accuracy of the assessment.

ATT&CK Techniques

Execution
7 techniques
Resource Development
12 techniques
Stealth
11 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Check Point Blind Eagle MAR 2025 — Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.
  2. Kaspersky BlindEagle AUG 2024 — Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.
  3. Recorded Future TAG-144 AUG 2025 — Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.
  4. QiAnXin APT-C-36 Feb2019 — QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

Intel Summary

38

Techniques

5

Tools

0

Campaigns

18

IOCs

0

Observed Data

8

Tactics

Tags

APT
Government Targeting
Espionage
Financially Motivated
South America
Government
Manufacturing
Financial Services

Details

MITRE ID
G0099
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c4d50cdf-87ce-407d-86d8-862883485842
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.