Threat actor
APT-C-36
Last fetched
APT-C-36 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 38 techniques and also known as 4 other names.
Also known as
Blind Eagle, TAG-144, AguilaCiega, APT-Q-98
Description
[APT-C-36](https://attack.mitre.org/groups/G0099) is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. [APT-C-36](https://attack.mitre.org/groups/G0099) has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.(Citation: QiAnXin APT-C-36 Feb2019)(Citation: Kaspersky BlindEagle AUG 2024)(Citation: Check Point Blind Eagle MAR 2025)(Citation: Recorded Future TAG-144 AUG 2025)
Techniques by tactic
Stealth
- T1027 · Obfuscated Files or Information
- T1027.003 · Steganography
- T1027.013 · Encrypted/Encoded File
- T1027.016 · Junk Code Insertion
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1055.012 · Process Hollowing
- T1480 · Execution Guardrails
- T1564.003 · Hidden Window
- T1574.001 · DLL
- T1684.001 · Impersonation
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to APT-C-36 today — this states the absence of a published link, not that APT-C-36 has no infrastructure.
References
- https://attack.mitre.org/groups/G0099
- https://research.checkpoint.com/2025/blind-eagle-and-justice-for-all/
- https://securelist.com/blindeagle-apt/113414/
- https://assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-0826.pdf
- https://web.archive.org/web/20190625182633if_/https://ti.360.net/blog/articles/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en/
- https://ti.360.net/blog/articles/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en/
- https://www.ecucert.gob.ec/wp-content/uploads/2022/03/alerta-APTs-2022-03-23.pdf
- https://blogs.blackberry.com/en/2023/02/blind-eagle-apt-c-36-targets-colombia
- https://lab52.io/blog/apt-c-36-recent-activity-analysis/
- https://www.trendmicro.com/en_ph/research/21/i/apt-c-36-updates-its-long-term-spam-campaign-against-south-ameri.html
- https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/
- https://attack.mitre.org/groups/G0099/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from APT-C-36 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.