Overview 95 indicators
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.
| domain | 64 | G0099-domain.txt |
| ipv4 | 20 | G0099.json |
| url | 9 | G0099.json |
| url_path | 2 | G0099.json |
Techniques 38 ATT&CK
Open in ATT&CK Navigator → or download the layer (38 techniques, layer 4.5)
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1055.012 Process Hollowing
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1105 Ingress Tool Transfer
- T1133 External Remote Services
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1480 Execution Guardrails
- T1534 Internal Spearphishing
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1568 Dynamic Resolution
- T1571 Non-Standard Port
- T1574.001 DLL
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1583.006 Web Services
- T1584.005 Botnet
- T1586.002 Email Accounts
- T1586.003 Cloud Accounts
- T1587.001 Malware
- T1588.001 Malware
- T1588.002 Tool
- T1593 Search Open Websites/Domains
- T1608.001 Upload Malware
- T1683.001 Written Content
- T1683.002 Audio-Visual Content
- T1684.001 Impersonation
Software 9
Principal sources 36 reports
Ranked by how many of this actor's indicators each report brought in.
- 20recordedfuture.com/research/tag-144s-persistent-grip-on-so…
- 16twitter.com/th3_protoCOL/status/1517144901871235072
- 16virustotal.com/gui/domain/polycomusa.com/community
- 16virustotal.com/gui/file/13e36170821628f9097862556e42cb…
- 12x.com/bigmacjpg/status/1841133075880632683
- 12gist.github.com/kirk-sayre-work/354d875086bb533b3095dc0…
- 12zscaler.com/blogs/security-research/blindeagle-targ…
- 12virustotal.com/gui/file/ec2dd6753e42f0e0b173a98f074aa4…
Related groups 3
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 95 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
recordedfuture.com/research/tag-144s-persistent-grip-on-so…
aseguradotelle.duckdns.org envio02-04.duckdns.org envio14-03.duckdns.org envio1414.duckdns.org envio19-05.duckdns.org envio21-05.duckdns.org envio2333.duckdns.org envio26-03.duckdns.org envio28-003.duckdns.org envio29.duckdns.org envio31-03.duckdns.org ojosostenerfebrero.duckdns.org qua25q.duckdns.org qua25qua.duckdns.org respaldito01.duckdns.org respaldito03.duckdns.org respaldomax3.duckdns.org respaldomax4.duckdns.org respaldomx1.duckdns.org respaldomx5.duckdns.org -
x.com/bigmacjpg/status/1841133075880632683 · gist.github.com/kirk-sayre-work/354d875086bb533b3095dc0…
domain pub-4c182737706e41d29aee6cc5517f834d.r2.dev domain pub-6346c84860d5480393a1799fb277dfdc.r2.dev ipv4 35.34.5.27:443 url http://104.168.32.148 url http://107.172.130.147 url http://134.19.177.44 url http://134.255.227.248 url http://172.232.184.131 url http://185.29.10.52 url http://198.46.129.134 url http://45.79.190.156 url http://72.5.43.53 -
zscaler.com/blogs/security-research/blindeagle-targ… · virustotal.com/gui/file/ec2dd6753e42f0e0b173a98f074aa4… · virustotal.com/gui/file/eb4a92271d1e034d3107a4acb892b3… · virustotal.com/gui/file/c2081fafabc9816a2392f3936489d7… · virustotal.com/gui/file/b63b7ab595fe60b92be73ba8b6e620… · virustotal.com/gui/file/9c10849b9f11cda1187e3827089261… · virustotal.com/gui/file/8038bd440b03f72d2f1147b2eb0642… · virustotal.com/gui/file/7d2862bafaa267a5b2e9dae56c9201… · virustotal.com/gui/file/50d29874cbfe0d2cb5aa6e30d56cb6…
domain edificiobaldeares.linkpc.net domain equipo.linkpc.net domain perfect5.publicvm.com domain perfect8.publicvm.com ipv4 128.90.108.115:4799 ipv4 128.90.115.167:4799 ipv4 128.90.115.93:4799 ipv4 128.90.115.95:4724 ipv4 128.90.130.185:4724 ipv4 69.167.10.207:4845 ipv4 69.167.11.9:4724 ipv4 69.167.8.118:9057 -
mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)
autgerman.com subirfact.com -
mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)
autgerman.autgerman.com -
twitter.com/dark0pcodes/status/1678920710872244225
cryptersandtools.minhacasa.tv vargasvargasabogadosnotificaciones.privat.lc -
twitter.com/0xToxin/status/1654802474534830080 · tria.ge/230506-mbyeqagg43/behavioral1 · tria.ge/230506-mdhr2sgg55/behavioral2
domain strekhost2066.duckdns.org ipv4 177.255.89.112:5220 -
twitter.com/Joseliyo_Jstnk/status/16540386424894423… · twitter.com/Joseliyo_Jstnk/status/16540386495149219…
domain chileimportaciones.cl url_path /udodinmauwa.txt -
otx.alienvault.com/pulse/64419d343c9d98fc279185f7
dian.server.tl -
twitter.com/0xToxin/status/1654802474534830080 · tria.ge/230506-mbyeqagg43/behavioral1 · tria.ge/230506-mdhr2sgg55/behavioral2
177.255.89.112:4203 -
research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-…
laminascol.linkpc.net systemwin.linkpc.net upxsystems.com -
twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…
/hAkDVgKdlfL7jcn/ -
twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…
therussian.polycomusa.com -
twitter.com/th3_protoCOL/status/1517144901871235072 · virustotal.com/gui/domain/polycomusa.com/community · virustotal.com/gui/file/13e36170821628f9097862556e42cb…
ajaxcoder.polycomusa.com axu87794.polycomusa.com giraffebear.polycomusa.com hellmagers.polycomusa.com host-rami.polycomusa.com mega.polycomusa.com polycomusa.com sainth.polycomusa.com sanctuary.polycomusa.com sicariop.polycomusa.com smakaf1.polycomusa.com yty0do.polycomusa.com zhost.polycomusa.com zvoracle.polycomusa.com -
virustotal.com/gui/file/ebbc37e280f15408a2ff17bec1151c…
domain defenderav.con-ip.com ipv4 181.130.5.112:33889 -
virustotal.com/gui/file/e81baa5e7bf0fe2ebeb07983e71d05…
domain marzo72022.con-ip.com ipv4 181.130.9.145:6525 -
virustotal.com/gui/file/8b437a76538722dc4535cbf3180005…
domain enero2022.con-ip.com ipv4 181.130.9.145:6522 -
virustotal.com/gui/file/f964f108f661de1c15e3cedee074cf…
45.147.231.85:12632 -
virustotal.com/gui/file/95eb3d6f61d5082bee11ea47a7c90c…
2.56.59.208:7075 -
virustotal.com/gui/file/8c2215d43e7cd77c90a424ca6c81c1…
2.56.57.27:8080 -
virustotal.com/gui/file/80e498268b8be964d5a74ca226218b…
62.197.136.252:1655 -
virustotal.com/gui/file/378e01925608bcd74544a5b5536c20…
103.151.124.233:666 -
twitter.com/1ZRR4H/status/1503572957595111427 · tria.ge/220314-3qe5padgh2
domain febenvi.duckdns.org ipv4 181.131.217.174:2050 -
twitter.com/HONKONE_K/status/1145536069435195392
medicosempresa.com -
ti.360.net/blog/articles/apt-c-36-continuous-attac…
ceoempresarialsas.com ceoseguros.com diangovcomuiscia.com ismaboli.com medicosco.publicvm.com mentes.publicvm.com -
ti.360.net/blog/articles/apt-c-36-continuous-attac…
ceosas.linkpc.net
Further reading 41
- assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-0826.p…
- attack.mitre.org/groups/G0099
- research.checkpoint.com/2025/blind-eagle-and-justice-for-all
- securelist.com/blindeagle-apt/113414
- web.archive.org/web/20190625182633if_/https://ti.360.ne…
- twitter.com/HONKONE_K/status/1145536069435195392
- twitter.com/th3_protoCOL/status/1517144901871235072
- otx.alienvault.com/pulse/64419d343c9d98fc279185f7
- twitter.com/0xToxin/status/1654802474534830080
- twitter.com/dark0pcodes/status/1678920710872244225
- virustotal.com/gui/file/e81baa5e7bf0fe2ebeb07983e71d05…
- virustotal.com/gui/file/b63b7ab595fe60b92be73ba8b6e620…
- tria.ge/220314-3qe5padgh2
- virustotal.com/gui/file/9c10849b9f11cda1187e3827089261…
- virustotal.com/gui/domain/polycomusa.com/community
- virustotal.com/gui/file/8c2215d43e7cd77c90a424ca6c81c1…
- tria.ge/230506-mdhr2sgg55/behavioral2
- virustotal.com/gui/file/8b437a76538722dc4535cbf3180005…
- virustotal.com/gui/file/eb4a92271d1e034d3107a4acb892b3…
- virustotal.com/gui/file/378e01925608bcd74544a5b5536c20…
- mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)
- virustotal.com/gui/file/80e498268b8be964d5a74ca226218b…
- recordedfuture.com/research/tag-144s-persistent-grip-on-so…
- virustotal.com/gui/file/ec2dd6753e42f0e0b173a98f074aa4…
- zscaler.com/blogs/security-research/blindeagle-targ…
- virustotal.com/gui/file/c2081fafabc9816a2392f3936489d7…
- virustotal.com/gui/file/50d29874cbfe0d2cb5aa6e30d56cb6…
- gist.github.com/kirk-sayre-work/354d875086bb533b3095dc0…
- virustotal.com/gui/file/8038bd440b03f72d2f1147b2eb0642…
- virustotal.com/gui/file/ebbc37e280f15408a2ff17bec1151c…
- x.com/bigmacjpg/status/1841133075880632683
- virustotal.com/gui/file/13e36170821628f9097862556e42cb…
- twitter.com/Joseliyo_Jstnk/status/16540386424894423…
- tria.ge/230506-mbyeqagg43/behavioral1
- ti.360.net/blog/articles/apt-c-36-continuous-attac…
- research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-…
- twitter.com/1ZRR4H/status/1503572957595111427
- twitter.com/Joseliyo_Jstnk/status/16540386495149219…
- virustotal.com/gui/file/7d2862bafaa267a5b2e9dae56c9201…
- virustotal.com/gui/file/f964f108f661de1c15e3cedee074cf…
1 more, and the report behind every indicator, in G0099.json.