APT-C-36

APT / StateG0099 ↗
Techniques (MITRE ATT&CK)38
SourceMITRE ATT&CK
Target categories: Petroleum, Manufacturing, Financial, Private sector, Government
Targeted regions: Ecuador · Colombia · Spain · Panama · Chile
Also known as:APT-Q-98AguilaCiegaBlind EagleTAG-144

About the group

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity39
Impact: High
T1566.001T1047T1133ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceExternal RemoteServicesLATLateral movementInternalSpearphishing

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 1866

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.128.234.124:443Remcosthreatfox
ip:port198.135.49.110:4489Remcosthreatfox
ip:port37.120.206.165:60507Remcosthreatfox
ip:port103.83.87.86:2404Remcosthreatfox
ip:port185.149.24.115:2404Remcosthreatfox
ip:port128.90.108.225:2424Remcosthreatfox
ip:port103.83.86.40:14642Remcosthreatfox
ip:port31.59.137.81:4565Remcosthreatfox
domainjustily.duckdns.orgRemcosthreatfox
ip:port46.246.6.8:5500DCRatthreatfox
ip:port216.227.218.4:8848DCRatthreatfox
ip:port128.90.102.158:7000DCRatthreatfox
ip:port103.57.250.246:9015DCRatthreatfox
ip:port128.90.108.89:2424Remcosthreatfox
ip:port103.254.61.170:3889Remcosthreatfox
ip:port46.246.14.21:5987Remcosthreatfox
ip:port194.116.236.83:15800Remcosthreatfox
ip:port94.143.143.253:8090DCRatthreatfox
ip:port45.76.161.231:8848DCRatthreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
ip:port204.44.93.119:7878Remcosthreatfox
ip:port128.90.108.50:2424Remcosthreatfox
ip:port128.90.102.194:2015Remcosthreatfox
ip:port43.228.157.72:1208Remcosthreatfox
ip:port102.220.163.130:14644Remcosthreatfox

+1866 indicators in total. See them all on the IOCs page.

APT-C-36 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →