Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BlindEagle

36
Global rank
14
Month rank
13 infographic chevron week
Week rank
0
IOCs

BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.

RAT
Type
Unknown
Origin
1 March, 2018
First seen
17 September, 2026
Last seen

How to analyze BlindEagle with ANY.RUN

RAT
Type
Unknown
Origin
1 March, 2018
First seen
17 September, 2026
Last seen

IOCs

IP addresses
142.251.20.94
142.250.154.95
142.251.150.119
151.101.129.91
151.101.1.91
151.101.193.91
74.178.76.128
20.190.159.75
52.110.17.59
52.111.243.8
52.110.17.75
88.221.169.152
48.209.138.189
131.253.33.203
162.241.60.30
151.101.65.91
48.202.208.48
48.192.1.64
142.251.20.113
48.209.138.168
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
0e60b52689f3627486b9a77bb4f88bea0d8665a94f7f1ffc960a1fbc427626b7
20de375707692099b3132084695377ce5fec0aec05813dedcce094b8eda44386
7bfbc8202b8cdbdcc597a0e789240f0dc0b0e94fa6597e576eaf436bc6223e18
1bc9035381c4e27fdea51b0692d8b88de4fc387f0b8a6b6307d1da115f6e56e8
c1f5c58aa854ace0b6653adc98381dbe7132a115242c7fead3398c56ccdc35f1
d1614ad99aded9f6f5c1be7fe7ffa5124bd04a526580da3818ea8a954e852aa6
792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
078648c042b9b08483ce246b7f01371072541a2e90d1beb0c8009a6118cbd965
d27d5b27030f4725249377951beb89e84a90a0e8241f0d5fd80ea59c1606e761
7d99fec08182a5b95d18d1569edaa2c60c2aafbd15a56d8882f22f3b395e6460
7ed09f7d2bd632f70077a4ae4f2bd2f3fb654b03cd72652f51678b0c7d027f25
614be0169ec36e67223eb9645a98da66dbfde5dfbb89bb064f428aaeabdd9d97
000e3a78c72a210ca3b5417a3cdd294fbce2a31661601c9d594c75cf2800571c
cbe2dc6abfe25bead60f4dfaf419fc0f441ff8a8dd4a2febf5553be1cbd90c49
7dbbea2dd387eeb85e1f56e02fc9989acde570cd43bfef2c2a827093ba87da6d
af5570f5a1810b7af78caf4bc70a660f0df51e42baf91d4de5b2328de0e83dfc
86a3e68762720abe870d1396794850220935115d3ccc8bb134ffa521244e3ef8
b6b10a07faa634027f3780e77fc3b165dcf7d37e800195bff5e147ccc492b828
Domains
region1.analytics.google.com
ep2.adtrafficquality.google
go.microsoft.com
settings-win.data.microsoft.com
spocs.getpocket.com
www.wikipedia.org
ecs.office.com
stats.g.doubleclick.net
ads-img.mozilla.org
d156sk07toobyl.cloudfront.net
www.reddit.com
aus5.mozilla.org
content-signature-2.cdn.mozilla.net
ep1.adtrafficquality.google
www.youtube.com
client.wns.windows.com
edgedl.me.gvt1.com
messaging.lifecycle.office.com
nexusrules.officeapps.live.com
google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://ecs.office.com/config/v2/office/outlook/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=outlook&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=outlook.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7bd0db2565-ec47-4f9b-9c88-2f736a514594%7d&labmachine=false
https://roaming.svc.cloud.microsoft/rs/roamingsoapservice.svc
https://login.live.com/ppsecure/deviceaddcredential.srf
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://self.events.data.microsoft.com/onecollector/1.0/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1666
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3504
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6612
comments 0

BlindEagle Malware Exposed: Steganography, Banking Trojans, and 9,000 Victims in One Campaign

Key Takeaways

  • BlindEagle is active and evolving. Operating since at least 2018, the group continuously updates its toolset, adding DLL sideloading, steganography, and new RAT variants.

  • The threat is primarily regional but not exclusively so. Colombia accounts for roughly 87% of known victims, but documented campaigns have reached Ecuador, Chile, Panama, and Spain — and any multinational organization with regional presence is potentially exposed.

  • Phishing is the gateway. Every BlindEagle intrusion begins with a convincing impersonation of a trusted government or financial authority.

  • Commodity RATs, sophisticated impact. Modified open-source RATs equipped with banking credential interception, keylogging, and remote access give the group everything it needs for both espionage and financial fraud.

  • Detection requires behavioral context, not just signatures. The group's use of legitimate platforms (GitHub, Discord, Google Drive) for payload staging, process hollowing for evasion, and DDNS for C2 rotation makes static indicator matching alone insufficient — behavioral detection and up-to-date intelligence are essential.

  • The infection chain is complex but detectable: phishing → geolocation filter → VBScript dropper → steganographic payload → process injection → RAT persistence — leaves multiple detection opportunities for organizations with proper monitoring in place.

  • Proactively defend with ANY.RUN’s Threat Intelligence Feeds for real-time IOC blocking and Threat Intelligence Lookup for rapid investigation of suspicious artifacts — combining both strengthens detection and response against evolving threats like BlindEagle. destinationIP:"181.134.198.53".

IP linked to BlindEagle campaigns Malicious IP linked to BlindEagle campaigns

What is BlindEagle?

BlindEagle is a South American APT group with a dual mandate: intelligence gathering and financial theft. Unlike many nation-state actors that rely on bespoke, sophisticated malware, BlindEagle operates with lean efficiency: adopting and customizing widely available open-source RATs, layering them within multi-stage infection chains, and constantly rotating tools to frustrate defenders.

The group has maintained a years-long targeting pattern — predominantly Colombia, and secondarily Ecuador, Chile, Panama, and Spain — with remarkable consistency. Their phishing emails convincingly impersonate Colombia's tax authority (DIAN), the Attorney General's Office, the Foreign Affairs Ministry, the judicial system, and major financial institutions. Victims receive what looks like an urgent legal notice or government document; one click sets an elaborate infection cascade in motion.

The group's RAT arsenal has included AsyncRAT, RemcosRAT, njRAT, LimeRAT, BitRAT, QuasarRAT, and DCRat, each modified with additional capabilities tailored to the campaign at hand. In espionage operations, these tools capture keystrokes, take screenshots, activate webcams, and exfiltrate files. In financially motivated campaigns, they transform into banking trojans intercepting credentials for Colombian financial institutions in real time.

The group uses geolocation filtering via URL shorteners: anyone accessing a malicious link from outside the targeted country is silently redirected to the legitimate website of whichever government body is being impersonated. This deflects automated threat hunters and frustrates researchers, while keeping infection rates high among intended targets.

ANY.RUN’s Interactive Sandbox allows to safely detonate FlowerStorm samples and analyse full attack chain:

View sandbox analysis

BlindEagle analysis in Interactive Sandbox BlindEagle detonated in Interactive Sandbox

How BlindEagle Threatens Businesses and Organizations

BlindEagle presents serious risks to organizations because it combines stealth, persistence, and operational flexibility.

Key business risks include:

  • Credential theft and account compromise. Stolen credentials may provide attackers with access to VPNs, email environments, cloud platforms, and internal systems.
  • Espionage and sensitive data exposure. Government agencies, financial institutions, and enterprises risk exposure of confidential documents, communications, and strategic data.
  • Operational disruption. Remote access malware enables attackers to manipulate systems, disable defenses, or prepare follow-on attacks.
  • Supply chain and trust exploitation. BlindEagle frequently abuses trusted internal email accounts, making phishing campaigns significantly harder for employees and security tools to identify.
  • Long-term persistence. RAT-based infections allow threat actors to maintain footholds inside networks for extended periods, increasing the risk of lateral movement and secondary payload deployment.
  • Regulatory and compliance exposure. Organizations handling citizen, healthcare, financial, or legal information may face legal consequences after a breach involving sensitive data exfiltration.

For CISOs and SOC teams, BlindEagle is particularly dangerous because its activity often blends into legitimate workflows. The attack chain can look like normal document sharing, judicial notifications, or internal communications until malware execution has already begun.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

Colombia accounts for approximately 87% of observed victims, reflecting the group's core focus. Ecuador, Chile, Panama, and Spain have also been targeted in documented campaigns, indicating the group is willing to expand when the opportunity presents itself. Sectors at heightened risk:

  • Government and public institutions: BlindEagle routinely impersonates and targets judicial bodies, tax agencies, immigration authorities, and peace negotiation bodies. The group specifically targeted Colombia's judicial institutions in campaigns running through early 2025, infecting over 9,000 victims in a single wave.
  • Financial services: Banks, insurance companies, and fintech firms are prime targets. A 2024 campaign focused specifically on Colombia's insurance sector, delivering a customized Quasar RAT designed to steal banking credentials.
  • Energy, oil, and gas: The group has actively targeted this sector since at least 2018, likely for both espionage and operational intelligence.
  • Healthcare and education: Campaigns have swept up hospitals, universities, and health agencies, which tend to have broader attack surfaces and less mature security postures.
  • Law enforcement and immigration: BlindEagle has impersonated and targeted law enforcement and immigration agencies, adding a dimension of intelligence collection around state security activities.

Any organization with employees in Colombia or other targeted Latin American countries including multinational companies with regional offices should consider itself within potential targeting range.

The Evolution of BlindEagle: Key Milestones

2018: Origins

BlindEagle begins operations, primarily targeting Colombian government institutions and financial sector entities. Early campaigns use basic phishing and off-the-shelf RATs, establishing the operational playbook the group will refine over the following years.

2019–2021: Expanding the toolkit

The group cycles through successive RATs — Quasar RAT, AsyncRAT, LimeRAT, BitRAT — demonstrating a pattern of adopting whatever commodity tool best fits the current campaign. Geolocation filtering via URL shorteners becomes a signature defensive tactic.

2022: Remcos and new targets

BlindEagle adds Remcos RAT to its arsenal, deploying it against government entities, private companies, and individuals in Colombia. The group begins experimenting with more elaborate infection chains, including password-protected archives hosted on Google Drive.

Early 2023: Ecuador targeting and sharpened tools

A notable campaign targets Ecuadorian organizations with a refined infection chain, incorporating living-off-the-land techniques (specifically the abuse of mshta) alongside a modified Quasar RAT configured to intercept banking credentials. Fake UUE files and Fsociety-based tooling appear in Colombian campaigns targeting judicial, financial, health, law enforcement, and immigration entities.

Mid-2023

Agent Tesla and expanding surveillance. BlindEagle transitions from njRAT to Agent Tesla as its primary implant in one campaign wave, signaling intent to broaden its surveillance capabilities.

2024: Steganography, DLL sideloading, and the njRAT pivot

BlindEagle begins hiding payloads inside images using steganography, and experiments with DLL sideloading — a technique previously uncharacteristic of the group. Portuguese-language artifacts begin appearing in malicious code, suggesting possible Brazilian involvement or deliberate misdirection. A dedicated campaign targets Colombia's insurance sector using BlotchyQuasar (a customized Quasar RAT variant), initiated via phishing emails impersonating Colombia's tax authority DIAN.

Late 2024–Early 2025

Justice for All campaign. A series of campaigns target Colombian judicial institutions, delivering malicious .url files that exploit behavior similar to CVE-2024-43451 — a Windows NTLMv2 hash disclosure vulnerability. Simply right-clicking, deleting, or dragging the file triggers a WebDAV request that notifies the attacker of the download. The PARAISO campaign alone infects over 1,600 victims with Remcos RAT. Total infections across this campaign wave approach 9,000. GitHub and Bitbucket repositories are abused as distribution platforms for final-stage payloads.

2025: Continued activity and supply chain risk

Darktrace identifies fresh BlindEagle activity targeting customers in Latin America through mid-2025. Researchers link BlindEagle infrastructure to Proton66, a bulletproof hosting provider. The group continues to evolve, with new campaigns targeting Colombian government agencies using DCRat and novel loaders. MITRE ATT&CK formally tracks the group as G0099, cataloguing its growing technique set.

How BlindEagle Gets Into Systems and Spreads

BlindEagle's intrusion methodology is highly consistent across campaigns, making it both predictable in pattern and effective in execution.

Stage 1 — Phishing lure

Everything begins with a carefully crafted phishing email. BlindEagle impersonates trusted institutions: Colombia's tax authority (DIAN), the Attorney General's Office, the judicial system, or major banks. Emails contain urgent language — a tax notice, a court summons, a legal complaint — designed to compel the recipient to act immediately. Attachments may appear to be PDFs or Word documents; links in the email body direct victims to download what appears to be official documentation.

Stage 2 — Geolocation filtering

Before any malicious content is served, a URL shortener checks the victim's geographic location. Connections from outside the targeted country are silently redirected to the legitimate website of the impersonated institution.

Stage 3 — Initial dropper

The victim downloads a compressed archive — ZIP, LHA, or UUE format — containing what appears to be an official document. Inside are Visual Basic Scripts (VBScripts) that, when executed, use WScript, XMLHTTP objects, or PowerShell commands to reach out to attacker-controlled servers or legitimate public platforms (GitHub, Pastebin, Discord, Bitbucket, Google Drive) to download the next-stage payload.

Stage 4 — Intermediate payload

The second-stage artifact may be a text file (with base64 or ASCII-encoded payload), an image file (with the payload concealed via steganography), or a .NET executable masquerading as a legitimate application. The initial dropper decodes and extracts this content, producing an intermediate DLL or .NET injector.

Stage 5 — Process injection and persistence

The injector loads the final RAT payload into the memory of a legitimate Windows process using process hollowing — a technique that causes the malicious code to execute under the guise of a trusted application, evading process-based security tools. The malware then writes itself into the Windows Registry to survive reboots. Command-and-control (C2) communications are established using Dynamic DNS services such as DuckDNS, which allow high IP rotation and rapid subdomain creation, making infrastructure takedown difficult.

Stage 6 — Post-compromise activity

With the RAT running, BlindEagle operators have full remote access: keylogging, screenshot capture, webcam activation, file exfiltration, remote desktop control, and — in financial campaigns — real-time interception of banking credentials as victims navigate to financial websites.

How BlindEagle Functions: Technical Mechanics

RAT rotation and customization

BlindEagle does not develop proprietary malware. Instead, it sources open-source or commodity RATs — AsyncRAT, Remcos, njRAT, LimeRAT, BitRAT, QuasarRAT, DCRat — and customizes them for each campaign. Modifications include adding keylogging routines tuned to specific banking websites, installing secondary plugin frameworks for expanded capability, embedding espionage-focused features such as webcam activation and screen recording, and in at least one documented case, building a complete banking credential interception module into a Quasar RAT variant.

Steganography

BlindEagle has been observed hiding encoded payloads inside image files, using steganographic techniques to conceal malicious code in plain sight. The encoded content is extracted and decoded by the initial dropper before being executed.

Process hollowing

The group's preferred injection method involves hollowing out a legitimate Windows process, replacing its code with the RAT payload.

DLL sideloading

By placing a malicious DLL in a location where a legitimate application will load it, BlindEagle can execute arbitrary code under the cover of a trusted application without triggering standard detection rules.

Living-off-the-land (LotL)

BlindEagle makes extensive use of Windows-native tools and processes — PowerShell, WScript, mshta, the .NET framework — reducing reliance on easily detected third-party malicious executables. Using built-in system tools for malicious purposes blends attacker activity into normal operational noise.

C2 via trusted platforms

By hosting payloads and staging infrastructure on GitHub, Bitbucket, Google Drive, Discord, and Pastebin, BlindEagle benefits from the implicit trust that security tools and network filters extend to these platforms. Blocking them outright would break legitimate business workflows — making BlindEagle's use of them a deliberate and effective defense bypass.

BlindEagle Sample Sandbox Analysis

View this sandbox session to observe BlindEagle full kill chain, payload, connections, and processes.

Blind Eagle (APT-C-36) typically begins its campaigns with a phishing email disguised as a notification from a government agency, court, or financial organization. The email contains a link or attachment that encourages the recipient to download a file and run it:

BlindEagle analysis in Interactive Sandbox BlindEagle detonated in Interactive Sandbox

In more recent campaigns, the group uses malicious Internet Shortcut (.url) files instead of classic .lnk files. Such a file points to a UNC/WebDAV path, for example: \62.60.226[.]200@80\file\WondersharePDFelement.exe

(The name of the executable file often changes, and shortcuts that are literally one day old may already be outdated). The @80 indicates WebDAV over HTTP.

File static analysis in the sandbox File static analysis in the sandbox

After interacting with the file, the system attempts to connect to the remote resource via WebDAV, displaying an interactive dialog window:

File opening confirmation File opening confirmation

If the user confirms, we can see the launch of the specified file in the process details:

Processes linked to the file in the sandbox Processes linked to the file in the sandbox (Note the file path starting with \Device\Mup...) We can also see the WebDAV connection in the scan through the corresponding detection: WebDAV connection detected in the sandbox WebDAV connection detected in the sandbox

After launching the remote payload, behavior may vary, but most often we observe C2 network traffic from the additional payload downloaded from the network. RAT traffic received after launching the payload:

RAT detected in network traffic RAT detected in network traffic

Right away in the sandbox, we can check Network Threats and see detections for Remcos:

Remcos malware detected Remcos malware detected

And the data on connections:

Captured network connections Captured network connections

Additionally, we see that a log file was dropped:

Log file detected in the sandbox Log file detected in the sandbox

As a result, a Remcos RAT was downloaded, which is also visible in the detections:

Remcos RAT detected by the sandbox Remcos RAT detected by the sandbox

Using ANY.RUN sandbox analysis, we can see the entire chain: URL file loading → launching a remote executable file via WebDAV → downloading the malicious payload (BlindEagle most often delivers RATs) → actual operation of the received payload (traffic, dropped files) with detection of the specific malware family.

Besides Interactive Sandbox, ANY.RUN provides threat intelligence solutions that help to protect proactively against BlindEagle and similar threats.

Threat Intelligence Feeds can help businesses:

  • Detect emerging BlindEagle infrastructure;
  • Block malicious IPs, domains, and URLs associated with campaigns;
  • Monitor malware behavior patterns;
  • Correlate network telemetry with fresh indicators;
  • Enrich SIEM, SOAR, EDR, and firewall workflows;
  • Identify infrastructure reuse across campaigns.

Because BlindEagle frequently shifts payloads and hosting providers, real-time IOC enrichment is critical for reducing exposure windows.

Threat Intelligence Lookup helps analysts proactively investigate:

  • Suspicious hashes;
  • PowerShell artifacts;
  • Domains and IPs;
  • File relationships;
  • Behavioral patterns;
  • Similar malware samples linked to BlindEagle operations.

This enables faster threat hunting and incident triage, especially when organizations detect suspicious phishing emails or unusual RAT-like behavior.

Other key measures:

  • Robust email security with sandboxing and attachment scanning.
  • User training on phishing, especially legal/government-themed lures.
  • Endpoint detection and response (EDR) with behavioral monitoring.
  • Least-privilege access, network segmentation, and multi-factor authentication.
  • Regular patching and disabling unnecessary macros/scripts.
  • Monitoring for anomalous PowerShell/WMI usage and WebDAV connections

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BlindEagle has evolved into a persistent and sophisticated cyber threat actor capable of targeting governments, enterprises, and critical organizations with stealthy phishing campaigns and RAT-based malware.

Its combination of social engineering, PowerShell abuse, DLL sideloading, and evolving malware infrastructure makes it especially dangerous for organizations relying solely on signature-based defenses.

For modern security teams, protection against BlindEagle requires more than endpoint detection alone. It demands continuous threat intelligence, behavioral visibility, rapid IOC correlation, and proactive hunting capabilities capable of identifying campaigns before they escalate into full-scale compromise.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
GootLoader screenshot
GootLoader
gootloader
GootLoader is an initial-access-as-a-service malware that operates by delivering the GootKit banking trojan and other malicious payloads. It utilizes techniques such as fileless execution and process injection to avoid detection. The malware is often distributed through SEO poisoning and compromised websites, deceiving users into downloading infected files.
Read More
MicroStealer screenshot
MicroStealer
microstealer
MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.
Read More
Makop Ransomware screenshot
Makop is a Phobos-derived Ransomware-as-a-Service model that predominantly targets exposed and vulnerable RDP endpoints. Rather than executing as a standalone automated threat, human operators manually navigate the compromised network to escalate privileges, map assets, and disable active defense solutions before deploying the payload.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More