Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98
38
techniques
9
software
11,364
corpus matches
profile
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.
techniques
38 attributed · most-instrumented first
software
9 malware & tools attributed
QuasarRAT
S0262
Remcos
S0332
njRAT
S0385
Imminent Monitor
S0434
AsyncRAT
S1087
Caminho
S9016
DCRAT
S9017
HeartCrypt
S9018
PureCrypter
S9019
read this carefully
11,364 corpus matches is not attribution
That count is indicators which exhibit techniques APT-C-36 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+26 more techniques
showing 30 of 11,364
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.