Blind Eagle’s Cyber Shenanigans: Colombian Institutions Under Siege

Blind Eagle’s latest antics are targeting Colombian government and private sectors with a sneaky new campaign. The group, known for its fondness for file-sharing platforms like Google Drive and GitHub, is exploiting these to distribute malware. With over 1600 infections in one campaign, Blind Eagle proves it’s not just a menace, but an overachiever.

Pro Dashboard

Hot Take:

Watch out, Colombia! Blind Eagle is flapping its wings and dropping cyber-bombs on government institutions. This infamous group has taken a page from Microsoft’s patch notes and turned it into their own playbook. With tactics slicker than an eagle’s wingspan, they’ve got a plan that’s sure to ruffle some feathers in the cybersecurity world!

Key Points:

  • Blind Eagle, a.k.a. APT-C-36, targets Colombian institutions using malicious .url files.
  • The threats mimic effects of a patched vulnerability (CVE-2024-43451) without exploiting it directly.
  • WebDAV requests let attackers know when a file is downloaded and trigger further payloads.
  • Blind Eagle uses platforms like Bitbucket and GitHub to distribute payloads, including Remcos RAT.
  • Over 9,000 infections from a single campaign in December 2024 highlight the group’s impact.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?