Also known as: APT-C-36, Blind Eagle, cybercrime, first appeared around 2018, an Arabic-speaking, tracked as, methodologies, MuddyWater, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, deliver malicious .url files, The Gaza Cybergang, Gaza Cybergang, Gaza Cybergang Group
APT-C‑13 is a sophisticated APT that emerged around 2018 and operates under multiple monikers – including Blind Eagle, Gaza Cybergang Group, and APT‑C‑36. The threat actor has adopted a hybrid arsenal that combines off‑the‑shelf remote access trojans such as MoleRAT and Remcos with bespoke tools, creating a modular campaign architecture. Delivery vectors are heavily anchored in spear‑phishing campaigns featuring malicious documents or .url files disguised as PDFs; once executed, these payloads establish covert channels via nested SSH tunnels and Tor hidden services employing obfs4 to evade DPI. Once inside, the malware maps SMB (445) and RDP (3389) traffic to onion domains, enabling remote data exfiltration through WebDAV or HTTP/HTTPS back‑channels. Persistence is achieved by creating scheduled tasks that masquerade as legitimate software such as Opera GX or Dropbox, while system process creation (T1543) and boot‑time autostart scripts (T1037/T1547) grant endurance. The group exhibits swift tactical evolution, including rapid zero‑day exploitation—most recently CVE‑2024‑43451—and the ability to pivot between offensive capabilities depending on target exposure. APT-C‑13’s operations reflect a focus on espionage against governmental, industrial, and research institutions worldwide, with documented campaigns targeting public and private entities in the Middle East, North Africa, and South America. Its operational tempo reveals short dwell times coupled with precise, data‑driven exfiltration strategies aimed at high‑value strategic information.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT-C‑13, also known as APT‑C‑36 or Blind Eagle, is a state‑backed adversary that uses spear phishing with malicious .url files and WebDAV abuse to deliver remote access trojans and command‑and‑control infrastructure. The group rapidly adapts zero‑day exploits, leverages nested SSH/Tor tunnels, and maintains persistence through disguised scheduled tasks, targeting a wide spectrum of sectors across the Middle East, North Africa, and beyond.
Goals & Targeting
The primary objective of APT‑C‑13 is global cyber espionage, securing intelligence from governments, critical infrastructure, defense contractors, and research organizations. The group targets sectors that can yield geopolitical leverage or economic advantage, including energy, telecommunications, finance, healthcare, and advanced manufacturing. By exploiting zero‑day vulnerabilities rapidly, leveraging decentralized Tor‑based C2 channels, and maintaining persistence through legitimate‑looking services, the actor seeks to remain covert while extracting actionable intelligence for state sponsors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT‑C‑13 exhibits a pattern of rapid campaign deployment, often leveraging newly disclosed zero‑day vulnerabilities within days of public disclosure. The actor preferentially targets high‑profile government and critical infrastructure entities while also venturing into private industry where valuable data resides. Campaign lifecycles are short but intense, with evidence of 1,600+ infections from a single December 2024 deployment against Colombian institutions. Their operations maintain operational security through anonymizing techniques such as Tor hubs mapped to internal SMB/RDP services and the use of legitimate process names in scheduled tasks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information presented combines multiple public intel sources and observed IOC patterns, giving a moderate level of confidence that APT-C-13 encompasses both the Blind Eagle and Gaza Cybergang monikers. Attribution linking all aliases remains somewhat uncertain, as does the full extent of the group’s operational footprint beyond the documented 2024 campaigns. Key gaps include precise internal infrastructure details, long‑term persistence indicators, and confirmation of state sponsorship across all identified sectors.
No campaigns linked yet.
No observed data linked yet.
43
Techniques
47
Tools
0
Campaigns
76
IOCs
0
Observed Data
14
Tactics