Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APT-C-13

Also known as: APT-C-36, Blind Eagle, cybercrime, first appeared around 2018, an Arabic-speaking, tracked as, methodologies, MuddyWater, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, deliver malicious .url files, The Gaza Cybergang, Gaza Cybergang, Gaza Cybergang Group

Description

APT-C‑13 is a sophisticated APT that emerged around 2018 and operates under multiple monikers – including Blind Eagle, Gaza Cybergang Group, and APT‑C‑36. The threat actor has adopted a hybrid arsenal that combines off‑the‑shelf remote access trojans such as MoleRAT and Remcos with bespoke tools, creating a modular campaign architecture. Delivery vectors are heavily anchored in spear‑phishing campaigns featuring malicious documents or .url files disguised as PDFs; once executed, these payloads establish covert channels via nested SSH tunnels and Tor hidden services employing obfs4 to evade DPI. Once inside, the malware maps SMB (445) and RDP (3389) traffic to onion domains, enabling remote data exfiltration through WebDAV or HTTP/HTTPS back‑channels. Persistence is achieved by creating scheduled tasks that masquerade as legitimate software such as Opera GX or Dropbox, while system process creation (T1543) and boot‑time autostart scripts (T1037/T1547) grant endurance. The group exhibits swift tactical evolution, including rapid zero‑day exploitation—most recently CVE‑2024‑43451—and the ability to pivot between offensive capabilities depending on target exposure. APT-C‑13’s operations reflect a focus on espionage against governmental, industrial, and research institutions worldwide, with documented campaigns targeting public and private entities in the Middle East, North Africa, and South America. Its operational tempo reveals short dwell times coupled with precise, data‑driven exfiltration strategies aimed at high‑value strategic information.

Goals & Targeting

Targeted Sectors

Government
Energy
Defense
Telecommunications
Financial services
Healthcare
Education
Manufacturing
Media
Non profit
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Retail
Aerospace
Mining
Gaming
Information technology
Think tank
Transportation
Chemical
Oil gas
Legal services
Nuclear
Utilities
Entertainment
Maritime
Construction

Targeted Countries / Regions

CN
US
RU
VN
IR
GB
JP
IL
UA
IN
AU
SA
PK
TW
AE
SG
KR
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

APT-C‑13, also known as APT‑C‑36 or Blind Eagle, is a state‑backed adversary that uses spear phishing with malicious .url files and WebDAV abuse to deliver remote access trojans and command‑and‑control infrastructure. The group rapidly adapts zero‑day exploits, leverages nested SSH/Tor tunnels, and maintains persistence through disguised scheduled tasks, targeting a wide spectrum of sectors across the Middle East, North Africa, and beyond.

Goals & Targeting

The primary objective of APT‑C‑13 is global cyber espionage, securing intelligence from governments, critical infrastructure, defense contractors, and research organizations. The group targets sectors that can yield geopolitical leverage or economic advantage, including energy, telecommunications, finance, healthcare, and advanced manufacturing. By exploiting zero‑day vulnerabilities rapidly, leveraging decentralized Tor‑based C2 channels, and maintaining persistence through legitimate‑looking services, the actor seeks to remain covert while extracting actionable intelligence for state sponsors.

Enhanced Description

Key Capabilities

  • Delivery via malicious .url files
  • Triggering WebDAV requests for exfiltration or download notifications
  • Rapid adaptation of zero‑day exploit variants within days
  • Spear-phishing with malicious document attachments
  • File-based malware delivery using Remote Access Trojans
  • Targeting both public and private sector entities in the Middle East/North Africa
  • Use of nested SSH and Tor tunnel architecture for covert communications
  • Persistence via scheduled tasks masquerading as legitimate applications
  • Obfuscation of Tor traffic with obfs4 protocol

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Command and Control
Credential Access
Collection
Exfiltration
Defense Evasion

ATT&CK Techniques

T1566.001
T1071.001
T1105
T1037
T1583
T1543
T1133
T1547
T1119
T1059
T1087
T1083
T1573
T1048
T1041

Software / Tooling

MoleRAT
Remcos RAT
Cobalt Strike
BlackByte

Campaigns & Victims

APT‑C‑13 exhibits a pattern of rapid campaign deployment, often leveraging newly disclosed zero‑day vulnerabilities within days of public disclosure. The actor preferentially targets high‑profile government and critical infrastructure entities while also venturing into private industry where valuable data resides. Campaign lifecycles are short but intense, with evidence of 1,600+ infections from a single December 2024 deployment against Colombian institutions. Their operations maintain operational security through anonymizing techniques such as Tor hubs mapped to internal SMB/RDP services and the use of legitimate process names in scheduled tasks.

IOC Patterns

  • Malicious .url file artefacts
  • WebDAV request patterns used for exfiltration or notification
  • CVE-2024-43451 exploitation activity
  • NTLMv2 hash exposure indicators
  • Spear phishing email with malicious document attachment
  • Obfuscated Tor traffic using obfs4

Recommended Actions

  • Apply the Microsoft patch for CVE‑2024‑43451 immediately.
  • Deploy endpoint protection with heuristics for .url file execution and WebDAV access patterns.
  • Implement advanced email filtering, including attachment sandboxing and spoof detection to block spear‑phishing documents.
  • Monitor network traffic for anomalous WebDAV requests or outbound connections to onion domains.
  • Configure scheduled task monitoring to flag tasks that mimic legitimate software (e.g., Opera GX, Dropbox).
  • Utilize threat intelligence feeds for .url file indicators, Tor hidden service lists, and CVE activity.
  • Conduct security awareness training emphasizing spear‑phishing detection and safe attachment handling.
  • Enforce least privilege and MFA on all privileged accounts to mitigate credential compromise.

Suggested Tags

APT-C-13
APT-C-36
Blind Eagle
Gaza Cybergang Group
malicious .url file delivery
WebDAV abuse
CVE‑2024-43451 exploitation
Rapid adaptation
MoleRAT
Remote Access Trojan
Spear phishing

Confidence Assessment

The information presented combines multiple public intel sources and observed IOC patterns, giving a moderate level of confidence that APT-C-13 encompasses both the Blind Eagle and Gaza Cybergang monikers. Attribution linking all aliases remains somewhat uncertain, as does the full extent of the group’s operational footprint beyond the documented 2024 campaigns. Key gaps include precise internal infrastructure details, long‑term persistence indicators, and confirmation of state sponsorship across all identified sectors.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 8 Domain 7 SHA-256 Hash 3 IPv4 Address 1 MD5 Hash 1

References

  1. www.cybereason.com — Cited by web research for: an Arabic-speaking
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. research.checkpoint.com — Cited by web research for: deliver malicious .url files
  4. attack.mitre.org — Cited by web research for: T1566
  5. www.esentire.com — Cited by web research for: T1055.012
  6. www.trendmicro.com — Cited by web research for: Moriya
  7. www.cybereason.com — Cited by web research for: Notifications.exe
  8. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451 — Cited by AI analysis.
  9. https://attack.mitre.org/techniques/T1566/ — Cited by AI analysis.

Intel Summary

43

Techniques

47

Tools

0

Campaigns

76

IOCs

0

Observed Data

14

Tactics

Tags

APT
Phishing
Government Targeting
Hacktivism
state-sponsored
cyber espionage
government
energy
defense
APT-C-13
APT-C-36
Blind Eagle
Gaza Cybergang Group
malicious .url file delivery
WebDAV abuse
CVE‑2024-43451 exploitation
Rapid adaptation
MoleRAT
Remote Access Trojan
Spear phishing

Details

Type
Apt
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
50%
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.