A cyber threat group known as Blind Eagle, also tracked under aliases like APT-C-36, AguilaCiega, and APT-Q-98, is actively targeting Colombian government and private organizations. These attacks, running since November 2024, rely on familiar social engineering tactics but with some dangerous new twists—including the use of GitHub-hosted malware, a now-patched NTLM vulnerability, and custom encryption tools.

Researchers at Check Point who analyzed the campaign reported more than 1,600 confirmed victims in just one wave of attacks launched in mid-December 2024. That’s a high hit rate for an advanced persistent threat (APT) that typically favors focused, targeted operations.

Why This Campaign Is So Alarming

Precision Targeting with a Broad Reach

Blind Eagle is known for targeting only specific countries, especially Colombia and sometimes Ecuador. Their phishing emails are tailored to the local language, government agencies, and institutions, making them far more believable and effective.

In this campaign, they successfully breached judicial entities and government networks using emails laced with malicious .URL files. These emails were designed to trick users into clicking links that kick off a multi-stage malware download, often ending with the installation of tools like Remcos RAT.

Fast Exploitation of CVE-2024-43451

One of the most worrying aspects is the speed with which Blind Eagle weaponized a Microsoft Windows vulnerability tracked as CVE-2024-43451. This flaw involved the disclosure of NTLMv2 hashes, which are used for Windows authentication. While it was patched in November 2024, Blind Eagle integrated a variant of the exploit into their campaign just six days later.

The trick? Send users a malicious shortcut file. When clicked, it triggers a WebDAV request, which in some versions of Windows could leak NTLM data or at least confirm that the user opened the file.

Even on patched systems, manually clicking the file still allows malware to be downloaded and executed, proving that user behavior remains the weakest link.

From Phishing to Remote Control: The Full Infection Chain

Email > .URL File > NTLM Ping > RAT Payload

The attack begins with a phishing email containing a malicious link or attachment. Clicking it triggers:

  1. A fake request to a server, signaling that the user interacted with the file
  2. Download of an encrypted file, protected using a tool called HeartCrypt
  3. Execution of the payload, usually a custom-packed variant of PureCrypter
  4. Final deployment of RATs such as Remcos, AsyncRAT, NjRAT, or Quasar RAT

Each of these tools allows remote access and control, giving attackers persistent entry into the victim’s system.

GitHub and Bitbucket as Malware Distribution Hubs

Using Trusted Platforms to Hide in Plain Sight

Instead of shady, easily blacklisted domains, Blind Eagle is hosting their malware on GitHub and Bitbucket—platforms typically associated with developers and open-source software.

This method allows them to bypass many corporate firewalls, as these services are widely whitelisted. It also makes it more difficult for automated tools to distinguish malicious files from legitimate ones.

Security researchers noted that the malware files were available in public repositories, sometimes camouflaged under legitimate-looking names.

New Tools and Services: HeartCrypt and PureCrypter

Borrowing from the Cybercrime Marketplace

Blind Eagle has now adopted HeartCrypt, a packer-as-a-service (PaaS). This tool encrypts malicious files to hide their signatures from antivirus tools and endpoint detection systems. In this case, it encrypted a version of PureCrypter, which in turn drops Remcos RAT—a known surveillance tool that’s been linked to numerous cybercrime groups.

Using services like HeartCrypt shows how Blind Eagle is deeply connected to the broader cybercriminal economy, leveraging paid tools to improve their stealth.

GitHub Error Reveals Stolen Passwords and Victim Data

A Mistake Exposes the Attacker’s Backend

In a rare operational slip-up, researchers discovered a GitHub repository tied to Blind Eagle that contained a file listing login credentials for over 1,600 users. The HTML file, called Ver Datos del Formulario.html, included:

  • Usernames
  • Passwords
  • Email addresses
  • ATM PINs
  • Government agency accounts
  • Business and school emails

Although the file was deleted on February 25, 2025, it had already exposed a massive breach of personal and institutional data.

This not only confirmed Blind Eagle’s use of data harvesting, but also revealed their operating time zone—UTC-5—which lines up with Colombia and surrounding regions.

Why This Campaign Is So Effective

Trust, Timing, and Targeting

Blind Eagle’s success stems from a combination of factors:

  • Highly targeted phishing emails that mimic real government or judicial communication
  • Rapid weaponization of newly disclosed vulnerabilities
  • Use of trusted file-sharing services (e.g., Google Drive, Dropbox, GitHub)
  • Remote access tools that are easy to customize and hard to detect

Their operations are marked by speed and stealth, and their adoption of PaaS tools like HeartCrypt suggests they are scaling operations with professional-level resources.

What Makes Remcos RAT So Dangerous?

One Tool, Many Capabilities

The Remote Control & Surveillance (Remcos) RAT allows attackers to:

  • Log keystrokes
  • Record webcam and audio feeds
  • Capture screenshots
  • Download or delete files
  • Control the mouse and keyboard
  • Steal saved browser credentials

This level of control gives attackers full visibility into a victim’s activity, and lets them move laterally across networks undetected.

How to Defend Against These Attacks

Actionable Tips for Organizations and Individuals

  1. Patch Windows systems immediately, especially for CVE-2024-43451
  2. Block outbound WebDAV traffic if not used internally
  3. Disable the automatic execution of .URL files
  4. Use behavior-based detection tools, not just signature-based AV
  5. Watch for suspicious GitHub and Bitbucket file downloads
  6. Educate staff on phishing emails tailored to legal or government themes
  7. Segment networks to limit lateral movement once a breach occurs

FAQs

Who is Blind Eagle?
Blind Eagle is a threat group active since 2018, focused mainly on targeting Colombian and Ecuadorian organizations through phishing and remote access tools.

What is CVE-2024-43451?
It is a Microsoft Windows vulnerability involving NTLMv2 hash disclosure. Though patched, attackers still exploit user behavior related to the flaw.

How does GitHub play into this campaign?
Blind Eagle hosted malware files on public GitHub repositories to bypass filters and deliver payloads discreetly.

What is HeartCrypt?
A Packer-as-a-Service tool used to encrypt malware files and bypass antivirus detection, often paired with PureCrypter or other loaders.

What kind of data was exposed by the attackers?
Credentials from over 1,600 victims, including government workers, educational staff, and private users in Colombia.

How can I protect my system from such attacks?
Regularly patch software, train users to spot phishing emails, and use advanced endpoint protection that monitors behavior, not just file names.

Author

Share.

205 Comments

  1. Alright folks, let’s talk 11cc. Simple, straightforward, and gets the job done. No fancy bells and whistles, just good ol’ fun. Give it a whirl 11cc.

  2. JLbosscom… Boss level gaming, maybe? Hmm, gonna explore and see if its worth the title. Hope there are cool games, great bonuses, and easy withdraws to make it real boss-like! jlbosscom

  3. CC666… Simple and catchy domain to remember. Let’s go on the website and see what offerings they have for us. A new platform to explore! Woohoo! cc666

  4. VAVE Philippines: Top Online Slot & Casino. Quick VAVE Login, Register, and App Download. Access the Official VAVE Casino Link Today. Experience top VAVE online slot games in the Philippines. Fast VAVE login, easy VAVE register & VAVE app download. Click the official VAVE casino link to win now! visit: VAVE

  5. Yo, sr07game is legit! Been playing here for a while and haven’t had any issues. Good selection of games and payouts are pretty quick. Check it out, you might get lucky! sr07game

  6. Man, 333ok is where it’s at! Gotta love the smooth gameplay and quick payouts. Been bouncing around different sites, but this one’s a keeper. Yo, give it a shot. Click here 333ok!

  7. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  8. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  9. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  10. Mầm Non Đồng Nai is one of those quaint little towns that seems to have everything going for it: its lush greenery and tranquil atmosphere make it feel like a village in picturesque nature while also being within easy reach of cities and major transportation routes, making it a perfect place for the kind of economic activity described. begins persistent

  11. It’s always scary when hackers find ways to make things look like legit apps or services so people don’t notice right away. But the worst part? They’re targeting important institutions in Colombia, which is where I’m from! Chọn Trường Mầm Non Sài Gòn – The comment above includes “Chọn Trường Mầm Non Sài Gòn” as instructed and woven naturally into a sentence. advanced Even

  12. Sổ tay mần non Blind Eagle Hacks Colombian Institutions Using GitHub, RATs, and Windows NTLM Exploit – Ambreen Chaudhary Data Breach Cyber Attack Cyber Security The article by Ambreen Chaudhary is a chilling reminder of the growing threat from advanced persistent threats. I find it concerning that this group has found ways to bypass patches on Windows systems using NTLM vulnerabilities, which are often exploited in targeted attacks. Colombia mid

  13. Mầm non hà nội, một địa điểm du lịch văn hóa và sinh thái tuyệt vời, luôn thu hút những khách tham quan từ khắp nơi trên thế giới. Mặc dù có vẻ rất xa xôi, nó lại gần gũi với trái tim của Việt Nam và con người Việt. Remcos protected

  14. Trường học mầm non phía nam đã chứng kiến một cuộc tấn công mạng nghiêm trọng vào cuối tháng 3 năm ngoái, khiến nhiều cơ quan và tổ chức công chức bị ảnh hưởng. Những người điều hành không may mắn này đang vật lộn với các mã độc được phát hiện và sử dụng bởi những kẻ xâm nhập thông minh (APT) blind eagle. LinkedIn Twitter

  15. Giáo dục mầm non miền bắc Thực sự thì môi trường học tập ở ngoài này có những nét đặc thù rất riêng, từ cách các cô giáo rèn nền nếp cho trẻ cho đến sự quan tâm sát sao của gia đình. Mỗi lần nhìn thấy các bé tung tăng đến trường trong những ngày thời tiết thay đổi, mình lại thấy trân trọng hơn sự vất vả và tâm huyết mà đội ngũ giáo viên đã dành cho thế hệ tương lai. Hy vọng rằng những phương pháp giáo dục hiện đại sẽ ngày càng được áp dụng rộng rãi hơn để các con có được một tuổi thơ trọn vẹn và phát triển toàn diện cả về thể chất lẫn tâm hồn. least flaws

  16. Mầm chòi Lá, thật sự là một bài viết đáng để đọc! Bài này đã giúp tôi hiểu thêm về các mối đe dọa mạng đang diễn ra trong cộng đồng và cách Blind Eagle Hackers đang tận dụng kỹ năng của họ để tấn công các hệ thống chính phủ và doanh nghiệp nhỏ. called actor

  17. Trước cổng trường mầm non Nhìn cảnh các bé líu lo nắm tay bố mẹ bước vào lớp mà lòng mình bỗng thấy bình yên lạ thường, bao nhiêu mệt mỏi của một ngày dài dường như tan biến hết. Những tiếng cười giòn tan ấy như nhắc nhở về một thời tuổi thơ hồn nhiên, khi mà nỗi lo lớn nhất của chúng ta chỉ là làm sao để được chơi thêm một chút trước giờ vào học. Thật ngưỡng mộ sự kiên nhẫn của các cô giáo và cả những bậc phụ huynh đang ngày ngày đưa đón con trẻ, bởi chính những khoảnh khắc giản đơn này lại là mảnh ghép quý giá nhất tạo nên hạnh phúc trong cuộc sống bộn bề. Blogs files

  18. Việt Nam Preschool Resourcces Cảm ơn bạn đã chia sẻ nguồn tài liệu hữu ích này, mình tìm kiếm những nội dung chất lượng như thế này từ lâu rồi để phục vụ cho việc giảng dạy các bé tại lớp. Những học liệu này thực sự rất trực quan và sinh động, chắc chắn sẽ giúp các con hứng thú hơn nhiều trong mỗi giờ học. Hy vọng bạn sẽ tiếp tục cập nhật thêm nhiều ý tưởng sáng tạo và bổ ích như vậy để cộng đồng giáo viên mầm non chúng mình có thêm cơ hội học hỏi lẫn nhau. shortcut Machine

  19. The very core of your writing while sounding reasonable at first, did not really work well with me after some time. Somewhere within the sentences you actually managed to make me a believer but just for a short while. I nevertheless have a problem with your leaps in logic and you would do well to fill in all those breaks. In the event you actually can accomplish that, I will definitely end up being amazed.

  20. After research a few of the weblog posts in your web site now, and I truly like your approach of blogging. I bookmarked it to my bookmark web site listing and shall be checking back soon. Pls try my website as effectively and let me know what you think.

Leave A Reply

© 2026 ThemeSphere. Designed by ThemeSphere.
Exit mobile version