← All actors Recent activity

APT-C-36 G0099

BLINDEAGLE · aguilaciega · apt-c-36 · apt-q-98 · apt36 · blind eagle · blotchyquasar · tag-144

Indicators
95
Source reports
36
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20182026

Overview 95 indicators

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.

domain64G0099-domain.txt
ipv420G0099.json
url9G0099.json
url_path2G0099.json

Techniques 38 ATT&CK

Open in ATT&CK Navigator → or download the layer (38 techniques, layer 4.5)

Software 9

Principal sources 36 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 95 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 20 domainthis year

    recordedfuture.com/research/tag-144s-persistent-grip-on-so…

    aseguradotelle.duckdns.org
    envio02-04.duckdns.org
    envio14-03.duckdns.org
    envio1414.duckdns.org
    envio19-05.duckdns.org
    envio21-05.duckdns.org
    envio2333.duckdns.org
    envio26-03.duckdns.org
    envio28-003.duckdns.org
    envio29.duckdns.org
    envio31-03.duckdns.org
    ojosostenerfebrero.duckdns.org
    qua25q.duckdns.org
    qua25qua.duckdns.org
    respaldito01.duckdns.org
    respaldito03.duckdns.org
    respaldomax3.duckdns.org
    respaldomax4.duckdns.org
    respaldomx1.duckdns.org
    respaldomx5.duckdns.org

  2. 2 domain, 1 ipv4, 9 url2 yrs ago

    x.com/bigmacjpg/status/1841133075880632683 · gist.github.com/kirk-sayre-work/354d875086bb533b3095dc0…

    domainpub-4c182737706e41d29aee6cc5517f834d.r2.dev
    domainpub-6346c84860d5480393a1799fb277dfdc.r2.dev
    ipv435.34.5.27:443
    urlhttp://104.168.32.148
    urlhttp://107.172.130.147
    urlhttp://134.19.177.44
    urlhttp://134.255.227.248
    urlhttp://172.232.184.131
    urlhttp://185.29.10.52
    urlhttp://198.46.129.134
    urlhttp://45.79.190.156
    urlhttp://72.5.43.53

  3. 4 domain, 8 ipv42 yrs ago

    zscaler.com/blogs/security-research/blindeagle-targ… · virustotal.com/gui/file/ec2dd6753e42f0e0b173a98f074aa4… · virustotal.com/gui/file/eb4a92271d1e034d3107a4acb892b3… · virustotal.com/gui/file/c2081fafabc9816a2392f3936489d7… · virustotal.com/gui/file/b63b7ab595fe60b92be73ba8b6e620… · virustotal.com/gui/file/9c10849b9f11cda1187e3827089261… · virustotal.com/gui/file/8038bd440b03f72d2f1147b2eb0642… · virustotal.com/gui/file/7d2862bafaa267a5b2e9dae56c9201… · virustotal.com/gui/file/50d29874cbfe0d2cb5aa6e30d56cb6…

    domainedificiobaldeares.linkpc.net
    domainequipo.linkpc.net
    domainperfect5.publicvm.com
    domainperfect8.publicvm.com
    ipv4128.90.108.115:4799
    ipv4128.90.115.167:4799
    ipv4128.90.115.93:4799
    ipv4128.90.115.95:4724
    ipv4128.90.130.185:4724
    ipv469.167.10.207:4845
    ipv469.167.11.9:4724
    ipv469.167.8.118:9057

  4. 2 domain3 yrs ago

    mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)

    autgerman.com
    subirfact.com

  5. 1 domain3 yrs ago

    mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)

    autgerman.autgerman.com

  6. 2 domain3 yrs ago

    twitter.com/dark0pcodes/status/1678920710872244225

    cryptersandtools.minhacasa.tv
    vargasvargasabogadosnotificaciones.privat.lc

  7. 1 domain, 1 ipv43 yrs ago

    twitter.com/0xToxin/status/1654802474534830080 · tria.ge/230506-mbyeqagg43/behavioral1 · tria.ge/230506-mdhr2sgg55/behavioral2

    domainstrekhost2066.duckdns.org
    ipv4177.255.89.112:5220

  8. 1 domain, 1 url_path3 yrs ago

    twitter.com/Joseliyo_Jstnk/status/16540386424894423… · twitter.com/Joseliyo_Jstnk/status/16540386495149219…

    domainchileimportaciones.cl
    url_path/udodinmauwa.txt

  9. 1 domain3 yrs ago

    otx.alienvault.com/pulse/64419d343c9d98fc279185f7

    dian.server.tl

  10. 1 ipv43 yrs ago

    twitter.com/0xToxin/status/1654802474534830080 · tria.ge/230506-mbyeqagg43/behavioral1 · tria.ge/230506-mdhr2sgg55/behavioral2

    177.255.89.112:4203

  11. 3 domain3 yrs ago

    research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-…

    laminascol.linkpc.net
    systemwin.linkpc.net
    upxsystems.com

  12. 1 url_path4 yrs ago

    twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…

    /hAkDVgKdlfL7jcn/

  13. 1 domain4 yrs ago

    twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…

    therussian.polycomusa.com

  14. 14 domain4 yrs ago

    twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…

    ajaxcoder.polycomusa.com
    axu87794.polycomusa.com
    giraffebear.polycomusa.com
    hellmagers.polycomusa.com
    host-rami.polycomusa.com
    mega.polycomusa.com
    polycomusa.com
    sainth.polycomusa.com
    sanctuary.polycomusa.com
    sicariop.polycomusa.com
    smakaf1.polycomusa.com
    yty0do.polycomusa.com
    zhost.polycomusa.com
    zvoracle.polycomusa.com

  15. 1 domain, 1 ipv44 yrs ago

    virustotal.com/gui/file/ebbc37e280f15408a2ff17bec1151c…

    domaindefenderav.con-ip.com
    ipv4181.130.5.112:33889

  16. 1 domain, 1 ipv44 yrs ago

    virustotal.com/gui/file/e81baa5e7bf0fe2ebeb07983e71d05…

    domainmarzo72022.con-ip.com
    ipv4181.130.9.145:6525

  17. 1 domain, 1 ipv44 yrs ago

    virustotal.com/gui/file/8b437a76538722dc4535cbf3180005…

    domainenero2022.con-ip.com
    ipv4181.130.9.145:6522

  18. 1 ipv44 yrs ago

    virustotal.com/gui/file/f964f108f661de1c15e3cedee074cf…

    45.147.231.85:12632

  19. 1 ipv44 yrs ago

    virustotal.com/gui/file/95eb3d6f61d5082bee11ea47a7c90c…

    2.56.59.208:7075

  20. 1 ipv44 yrs ago

    virustotal.com/gui/file/8c2215d43e7cd77c90a424ca6c81c1…

    2.56.57.27:8080

  21. 1 ipv44 yrs ago

    virustotal.com/gui/file/80e498268b8be964d5a74ca226218b…

    62.197.136.252:1655

  22. 1 ipv44 yrs ago

    virustotal.com/gui/file/378e01925608bcd74544a5b5536c20…

    103.151.124.233:666

  23. 1 domain, 1 ipv44 yrs ago

    twitter.com/1ZRR4H/status/1503572957595111427 · tria.ge/220314-3qe5padgh2

    domainfebenvi.duckdns.org
    ipv4181.131.217.174:2050

  24. 1 domain7 yrs ago

    twitter.com/HONKONE_K/status/1145536069435195392

    medicosempresa.com

  25. 6 domain7 yrs ago

    ti.360.net/blog/articles/apt-c-36-continuous-attac…

    ceoempresarialsas.com
    ceoseguros.com
    diangovcomuiscia.com
    ismaboli.com
    medicosco.publicvm.com
    mentes.publicvm.com

  26. 1 domain8 yrs ago

    ti.360.net/blog/articles/apt-c-36-continuous-attac…

    ceosas.linkpc.net

Further reading 41

1 more, and the report behind every indicator, in G0099.json.