APT-C-36
G00991 reportsaliases · APT-C-36 · Blind Eagle · TAG-144 · AguilaCiega · APT-Q-98
1
Reports
1
Techniques
1
Tactics
5
Countries
100%
Hunt coverage
5
Aliases
Analyst assessment — key judgments
- Signature techniques: T1590.005 (IP Addresses).
- Primary targeting: SE, CN, RU, IR.
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 100% of 1 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DormantLast 30d: 0 vs 0 prior (+0%)· first reported 2026-06-25 · last 2026-06-25
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Overview
Analyst triage
Intelligence summary
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.(Citation: QiAnXin APT-C-36 Feb2019)(Citation: Kaspersky BlindEagle AUG 2024)(Citation: Check Point Blind Eagle MAR 2025)(Citation: Recorded Future TAG-144 AUG 2025)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1590.005 · IP Addressesconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|