Also known as: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, APT-C-36, South America
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.(Citation: QiAnXin APT-C-36 Feb2019)(Citation: Kaspersky BlindEagle AUG 2024)(Citation: Check Point Blind Eagle MAR 2025)(Citation: Recorded Future TAG-144 AUG 2025)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT-C-36 is a suspected South American threat group engaged in espionage and financially motivated operations, targeting government institutions and entities in the financial, energy, and manufacturing sectors. The group's primary motivation is espionage, and its activities have been linked to the South American region. APT-C-36's capabilities and motivations suggest a high level of sophistication, with the ability to adapt and evolve its TTPs to evade detection and achieve its objectives.
Enhanced Description
APT-C-36, also known as Blind Eagle, TAG-144, AguilaCiega, APT-Q-98, and APT-C-36, is a suspected South American threat group that has been engaged in espionage and financially motivated operations since at least 2018. The group's primary motivation is espionage, and it has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries. APT-C-36's operations have been documented by multiple security firms, including QiAnXin, Kaspersky, Check Point, and Recorded Future, providing valuable insights into the group's tactics, techniques, and procedures (TTPs). The group's activities have been consistently linked to the South American region, with a focus on targeting critical infrastructure and sensitive information. APT-C-36's capabilities and motivations suggest a high level of sophistication, with the ability to adapt and evolve its TTPs to evade detection and achieve its objectives. The group's use of various aliases and its ability to operate undetected for extended periods highlight the importance of continuous monitoring and threat intelligence gathering to stay ahead of this threat. APT-C-36's TTPs are likely to continue evolving, making it essential for organizations to remain vigilant and implement robust defensive measures to protect against this threat. The threat actor's activities have significant implications for organizations operating in the government, manufacturing, and financial services sectors, particularly in Colombia and other Latin American countries.
Key Capabilities
MITRE ATT&CK Tactics
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, with multiple security firms providing insights into APT-C-36's TTPs. However, there are information gaps regarding the group's exact sophistication level, motivations, and affiliations, which could impact the accuracy of the assessment.
No campaigns linked yet.
No observed data linked yet.
38
Techniques
5
Tools
0
Campaigns
18
IOCs
0
Observed Data
8
Tactics