Live OTX pulse data from AlienVault and LevelBlue SpiderLabs exposes the operational infrastructure of APT-C-36 (Blind Eagle), a financially-motivated Latin American threat actor with a long history of targeting Colombian government entities and citizens. This latest investigation — titled Still Circling: Inside the Operator Behind the GitHub Loader — reveals a mature, self-service malware delivery pipeline that abuses legitimate GitHub repositories as staging infrastructure for malicious loaders and second-stage RAT payloads.
The attack chain is classic Blind Eagle tradecraft modernized: Colombian-themed phishing lures (fake judicial notification domains such as consultanotificacionesjuridicas.site — "consult legal notifications") deliver an initial loader, frequently an AutoIt-compiled backdoor (S0129), which retrieves RAT payloads staged in attacker-controlled GitHub repositories. The operator rotates between multiple commodity RAT families — AsyncRAT, DcRat, Remcos, and XWorm — indicating either a crypter/loader-as-a-service offering or a single operator A/B testing payload efficacy.
The most operationally significant finding: researchers pivoted from GitHub commit metadata to an operator email address, then cross-referenced it against stealer log databases — and located the operator's own compromised machine. The infected workstation contained the complete operational pipeline: crypter services, phishing kits, RAT builders, and victim stealer logs. This is a rare look inside the adversary's kitchen, and it confirms that stealer log marketplaces now serve double duty as threat intelligence sources for unmasking operators.
Objective: credential theft, financial fraud, and persistent remote access against Colombian government and civilian targets — with harvested stealer logs monetized or reused for follow-on compromise.
Threat Actor / Malware Profile
APT-C-36 (Blind Eagle)
A Spanish-speaking threat actor active since at least 2018, primarily targeting Colombian government, judicial, and financial sectors. Blind Eagle blends espionage-grade persistence with commodity cybercrime tooling, and is notorious for impersonating Colombian government institutions (DIAN tax authority, judicial branch, notary services) in phishing lures.
Malware Families in This Campaign
| Family | Role | Key Behaviors |
|---|---|---|
| AsyncRAT | Primary RAT | .NET-based; C2 over TCP with AES-encrypted channels; persistence via registry Run keys and scheduled tasks; keylogging, screen capture, credential theft from browsers |
| DcRat | Modular RAT | .NET fork of AsyncRAT lineage; plugin-based architecture; dynamic DNS C2 (note dccomicrat81.duckdns.org); anti-VM checks |
| Remcos | Commercial RAT | Sold legitimately, abused heavily; UAC bypass, process hollowing, credential harvesting; TLS-wrapped C2 |
| XWorm | Commodity RAT | .NET RAT with ransomware module, USB propagation, and clipper functionality; Telegram/Discord-based builder ecosystem |
| AutoIt backdoor (S0129) | Loader/stager | Compiled .a3x/.exe scripts decrypt and inject RAT payloads; frequently paired with obfuscated WScript droppers (see Wscript.txt in the IOC set) |
Attack Chain
- Delivery: Colombian judicial/legal-themed phishing email with malicious attachment or link to actor-controlled domain (e.g.,
creainovada.xyz/instructions/). - Stager: WScript/AutoIt loader retrieves payload from GitHub raw content or release assets — blending malicious traffic into trusted SaaS egress.
- Deployment: Loader decrypts and injects one of the four RAT families, often via crypter services observed on the operator's machine.
- C2: Dynamic DNS (DuckDNS) and low-reputation TLD infrastructure (
.xyz,.site). - Persistence: Registry Run keys, scheduled tasks, and startup folder entries depending on the RAT family.
- Exfiltration: Browser credential stores, keystrokes, and stealer-log formatted archives uploaded to operator infrastructure.
Anti-Analysis Techniques
- Payload staging on GitHub to defeat domain reputation controls
- Crypter services to repack RAT binaries per campaign
- AutoIt script obfuscation and WScript intermediate droppers
- Dynamic DNS C2 to survive static domain takedowns
- Geofenced lures targeting Colombian Spanish speakers only
IOC Analysis
The pulse contains 9 indicators across three types:
- Domains (5):
data-encoder.com,creainovada.xyz,consultanotificacionesjuridicas.site,simpmit.co, plus the malformedconfig.dataartifact (likely a truncated C2 config field — treat as context, not a blockable domain). - Hostname (1):
dccomicrat81.duckdns.org— dynamic DNS C2, consistent with DcRat operator naming conventions. Block DuckDNS subdomains at the resolver level only after confirming no legitimate business use; ideally alert on all*.duckdns.orgresolution from endpoints. - URLs (2):
http://creainovada.xyz/instructions/andhttp://creainovada.xyz/instructions/Wscript.txt— active loader staging paths. TheWscript.txtartifact is a textbook Blind Eagle trick: a script payload served with a.txtextension to evade content-type inspection, then renamed and executed by the phishing attachment.
Operationalization Guidance for SOC Teams
- Block at the edge: Push all domains/hostnames to DNS sinkhole, web proxy, and EDR network block lists immediately.
- Retro-hunt DNS: Query the last 90 days of DNS/proxy logs for any resolution of these indicators — a single hit means a workstation reached staging or C2.
- Pivot on infrastructure: Use passive DNS (VirusTotal, SecurityTrails, Validin) to enumerate co-hosted domains on the same IPs; Blind Eagle rotates lures frequently and sibling domains are high-fidelity.
- Decode the loader: Any retrieved
Wscript.txtor AutoIt script should be detonated in a sandbox (ANY.RUN, Triage) or decompiled with Exe2Aut / myAut2Exe for AutoIt binaries. Extract GitHub URLs from the decompiled source to enumerate the operator's repo inventory before takedown. - GitHub telemetry: If your proxy logs GitHub raw/release downloads, hunt for
raw.githubusercontent.comandgithub.com/*/releases/downloadrequests from workstations that do not belong to developers — this is the highest-signal behavioral pivot in this campaign.
Detection Engineering
---
title: Blind Eagle AutoIt Loader Execution via WScript
description: Detects WScript/CScript executing script files with suspicious extensions or from user-writable staging paths, consistent with APT-C-36 (Blind Eagle) AutoIt/WScript loader delivery observed staging payloads from GitHub.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_engine:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
selection_args:
CommandLine|contains:
- '.txt'
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Public\'
- '\Downloads\'
filter_legit:
CommandLine|contains:
- '\Program Files\'
- '\Windows\System32\'
condition: selection_engine and selection_args and not filter_legit
falsepositives:
- Rare legitimate administrative scripting from temp paths
level: high
tags:
- attack.execution
- attack.t1059.005
- attack.t1059.007
- attack.t1204.002
date: 2026/09/28
---
title: Non-Developer Process Downloading Payload from GitHub Raw or Releases
description: Detects script interpreters, Office apps, or RAT-stage tooling retrieving content from GitHub raw content or release asset URLs - Blind Eagle (APT-C-36) stages AsyncRAT, DcRat, Remcos and XWorm payloads in GitHub repositories.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_url:
CommandLine|contains:
- 'raw.githubusercontent.com'
- 'github.com'
- 'objects.githubusercontent.com'
selection_suspicious_parent:
ParentImage|endswith:
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\winword.exe'
- '\excel.exe'
- '\rundll32.exe'
condition: all of selection_*
falsepositives:
- Developer workstations and software update mechanisms using GitHub releases; scope exclusions by parent process or user context
level: high
tags:
- attack.command_and_control
- attack.t1105
- attack.t1071.001
date: 2026/09/28
---
title: AsyncRAT / DcRat Persistence via Registry Run Key or Scheduled Task
description: Detects persistence creation in Run keys or scheduled tasks pointing to user-writable paths, a common persistence pattern for AsyncRAT, DcRat, Remcos and XWorm deployed by APT-C-36 operators.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
category: registry_set
product: windows
detection:
selection_key:
TargetObject|contains:
- '\CurrentVersion\Run\'
- '\CurrentVersion\RunOnce\'
selection_value:
Details|contains:
- '\AppData\'
- '\Temp\'
- '\Public\'
- '\ProgramData\'
filter_known_good:
Details|contains:
- 'OneDrive'
- 'MicrosoftEdge'
- 'Teams'
condition: selection_key and selection_value and not filter_known_good
falsepositives:
- Legitimate user-context applications registering autostart entries; tune against an enterprise software baseline
level: high
tags:
- attack.persistence
- attack.t1060
- attack.t1547.001
date: 2026/09/28
// Blind Eagle (APT-C-36) Hunt: IOC matching + behavioral pivots for GitHub-staged RAT loaders
// Microsoft Sentinel / Defender XDR - run over last 30 days
let BlindEagleIoCs = dynamic([
"data-encoder.com",
"creainovada.xyz",
"consultanotificacionesjuridicas.site",
"simpmit.co",
"dccomicrat81.duckdns.org"
]);
let Lookback = 30d;
// Part 1: Direct IOC hits in network telemetry
let NetworkHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteUrl has_any (BlindEagleIoCs) or RemoteIP in (
// enrich via your threat intel connector if IPs are resolved separately
toscalar(DeviceNetworkEvents | where Timestamp > ago(Lookback)
| where RemoteUrl has_any (BlindEagleIoCs) | distinct RemoteIP)
)
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
| extend MatchType = "Direct IOC Network Hit";
// Part 2: DNS resolution of DuckDNS dynamic DNS (DcRat C2 pattern)
let DuckDnsHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteUrl endswith ".duckdns.org"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
| extend MatchType = "Dynamic DNS C2 Pattern";
// Part 3: Script interpreters pulling payloads from GitHub (loader staging behavior)
let GitHubStagerHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("wscript.exe", "cscript.exe", "mshta.exe", "powershell.exe", "cmd.exe", "rundll32.exe")
| where ProcessCommandLine has_any ("raw.githubusercontent.com", "github.com", "githubusercontent.com")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName
| extend MatchType = "GitHub Payload Staging via Script Interpreter";
// Part 4: WScript executing .txt-renamed scripts (Blind Eagle Wscript.txt tradecraft)
let TxtScriptHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("wscript.exe", "cscript.exe")
| where ProcessCommandLine has ".txt"
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName
| extend MatchType = "WScript Executing .txt Script";
union NetworkHits, DuckDnsHits, GitHubStagerHits, TxtScriptHits
| sort by Timestamp desc
# Blind Eagle (APT-C-36) Endpoint IOC & Artifact Hunt
# Checks for: campaign IOCs in DNS cache, Run-key persistence in user-writable paths,
# suspicious scheduled tasks, AutoIt/WScript staging artifacts, and active C2 connections.
# Run elevated on suspect endpoints. Review output before taking remediation action.
$Report = @()
Write-Host "[*] Checking DNS cache for campaign IOCs..." -ForegroundColor Cyan
$iocDomains = @("data-encoder.com","creainovada.xyz","consultanotificacionesjuridicas.site","simpmit.co","dccomicrat81.duckdns.org")
$dnsHits = Get-DnsClientCache | Where-Object { $e = $_.Entry; $iocDomains | Where-Object { $e -like "*$_*" } }
if ($dnsHits) { $Report += "[ALERT] DNS cache IOC hit:`n$($dnsHits | Out-String)" }
Write-Host "[*] Auditing Run / RunOnce persistence keys..." -ForegroundColor Cyan
$runKeys = @(
"HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce"
)
foreach ($key in $runKeys) {
if (Test-Path $key) {
Get-ItemProperty $key | ForEach-Object {
$_.PSObject.Properties | Where-Object {
$_.Name -notmatch '^PS' -and $_.Value -match 'AppData|Temp|Public|ProgramData|\.txt|wscript|\.a3x'
} | ForEach-Object {
$Report += "[ALERT] Suspicious autostart: $key :: $($_.Name) = $($_.Value)"
}
}
}
}
Write-Host "[*] Auditing scheduled tasks for user-path execution..." -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.State -ne 'Disabled' } | ForEach-Object {
$actions = ($_.Actions | Out-String)
if ($actions -match 'AppData|Temp\|wscript|cscript|\.a3x|powershell.*-enc') {
$Report += "[ALERT] Suspicious scheduled task: $($_.TaskName) :: $actions"
}
}
Write-Host "[*] Searching common staging directories for AutoIt/WScript artifacts..." -ForegroundColor Cyan
$stagingPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:PUBLIC","$env:USERPROFILE\Downloads")
foreach ($p in $stagingPaths) {
Get-ChildItem $p -Recurse -Depth 2 -ErrorAction SilentlyContinue |
Where-Object { $_.Extension -in '.a3x','.txt','.vbs','.js' -and $_.Length -gt 50KB } |
ForEach-Object { $Report += "[REVIEW] Possible staged script: $($_.FullName) ($([math]::Round($_.Length/1KB)) KB)" }
}
Write-Host "[*] Checking active connections to dynamic DNS / known C2..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
Where-Object { $_.RemotePort -in 6666,7777,8808,11778 -or $_.OwningProcess -in (Get-Process wscript,cscript,AutoIt3 -ErrorAction SilentlyContinue).Id } |
ForEach-Object {
$proc = (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName
$Report += "[REVIEW] Connection: $proc ($($_.OwningProcess)) -> $($_.RemoteAddress):$($_.RemotePort)"
}
Write-Host "`n===== HUNT RESULTS =====" -ForegroundColor Yellow
if ($Report.Count -eq 0) { Write-Host "[+] No Blind Eagle artifacts detected on this host." -ForegroundColor Green }
else { $Report | ForEach-Object { Write-Host "$_`n" -ForegroundColor Red } }
Response Priorities
Immediate (0–4 hours)
- Block all pulse indicators at DNS resolver, secure web gateway, and EDR network layers:
data-encoder.com,creainovada.xyz,consultanotificacionesjuridicas.site,simpmit.co,dccomicrat81.duckdns.org, and the fullcreainovada.xyz/instructions/URL paths. - Enable alerting (not blanket blocking) on
*.duckdns.orgresolution to catch rotated DcRat/XWorm C2 without breaking legitimate DDNS use. - Run the KQL hunt across the last 30 days of telemetry; any GitHub-staging or WScript
.txthits trigger an immediate endpoint isolation and memory capture (RATs are largely fileless post-injection). - Sweep mail gateways for Colombian judicial-themed lures referencing "notificaciones jurídicas," "consulta," or similar legal-notification phrasing.
Within 24 Hours
- Assume credential compromise on any host with an IOC hit. AsyncRAT, Remcos, and XWorm all harvest browser credential stores and session cookies. Force password resets and revoke active sessions/tokens (especially Microsoft 365 refresh tokens) for all users of affected machines.
- Check whether harvested credentials from your environment appear in stealer log marketplaces — the operator's own compromise via stealer logs proves this data circulates rapidly. Engage your dark web monitoring capability for corporate domain matches.
- Reimage confirmed-compromised endpoints rather than cleaning in place; multi-RAT deployment makes full artifact eradication unreliable.
- Rotate any service accounts or VPN credentials used on affected hosts.
Within 1 Week
- Restrict script interpreter abuse: deploy WDAC or AppLocker rules blocking WScript/CScript execution of files outside trusted extensions and paths; disable AutoIt (
AutoIt3.exe) execution enterprise-wide unless business-justified. - Gate GitHub egress: for non-developer endpoints, proxy-restrict
raw.githubusercontent.comand GitHub release-asset downloads, or at minimum log and alert on them. Blind Eagle's reliance on GitHub staging is a detection gift — use it. - Harden email controls for Spanish-language government-impersonation lures: attachment detonation for
.txt,.vbs,.js, and compiled script executables. - Add the Sigma rules above to your detection pipeline and validate with Atomic Red Team tests for T1059.005/T1547.001.
- Brief LATAM-facing business units on Blind Eagle's judicial-impersonation pretexts; this actor recycles lures across campaigns.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.