Back to Intelligence

APT-C-36 (Blind Eagle) GitHub Loader Campaign: AsyncRAT, DcRat, Remcos & XWorm Deployment Pipeline — OTX Detection Pack

SA
Security Arsenal Team
September 27, 2026
11 min read

Live OTX pulse data from AlienVault and LevelBlue SpiderLabs exposes the operational infrastructure of APT-C-36 (Blind Eagle), a financially-motivated Latin American threat actor with a long history of targeting Colombian government entities and citizens. This latest investigation — titled Still Circling: Inside the Operator Behind the GitHub Loader — reveals a mature, self-service malware delivery pipeline that abuses legitimate GitHub repositories as staging infrastructure for malicious loaders and second-stage RAT payloads.

The attack chain is classic Blind Eagle tradecraft modernized: Colombian-themed phishing lures (fake judicial notification domains such as consultanotificacionesjuridicas.site — "consult legal notifications") deliver an initial loader, frequently an AutoIt-compiled backdoor (S0129), which retrieves RAT payloads staged in attacker-controlled GitHub repositories. The operator rotates between multiple commodity RAT families — AsyncRAT, DcRat, Remcos, and XWorm — indicating either a crypter/loader-as-a-service offering or a single operator A/B testing payload efficacy.

The most operationally significant finding: researchers pivoted from GitHub commit metadata to an operator email address, then cross-referenced it against stealer log databases — and located the operator's own compromised machine. The infected workstation contained the complete operational pipeline: crypter services, phishing kits, RAT builders, and victim stealer logs. This is a rare look inside the adversary's kitchen, and it confirms that stealer log marketplaces now serve double duty as threat intelligence sources for unmasking operators.

Objective: credential theft, financial fraud, and persistent remote access against Colombian government and civilian targets — with harvested stealer logs monetized or reused for follow-on compromise.

Threat Actor / Malware Profile

APT-C-36 (Blind Eagle)

A Spanish-speaking threat actor active since at least 2018, primarily targeting Colombian government, judicial, and financial sectors. Blind Eagle blends espionage-grade persistence with commodity cybercrime tooling, and is notorious for impersonating Colombian government institutions (DIAN tax authority, judicial branch, notary services) in phishing lures.

Malware Families in This Campaign

FamilyRoleKey Behaviors
AsyncRATPrimary RAT.NET-based; C2 over TCP with AES-encrypted channels; persistence via registry Run keys and scheduled tasks; keylogging, screen capture, credential theft from browsers
DcRatModular RAT.NET fork of AsyncRAT lineage; plugin-based architecture; dynamic DNS C2 (note dccomicrat81.duckdns.org); anti-VM checks
RemcosCommercial RATSold legitimately, abused heavily; UAC bypass, process hollowing, credential harvesting; TLS-wrapped C2
XWormCommodity RAT.NET RAT with ransomware module, USB propagation, and clipper functionality; Telegram/Discord-based builder ecosystem
AutoIt backdoor (S0129)Loader/stagerCompiled .a3x/.exe scripts decrypt and inject RAT payloads; frequently paired with obfuscated WScript droppers (see Wscript.txt in the IOC set)

Attack Chain

  1. Delivery: Colombian judicial/legal-themed phishing email with malicious attachment or link to actor-controlled domain (e.g., creainovada.xyz/instructions/).
  2. Stager: WScript/AutoIt loader retrieves payload from GitHub raw content or release assets — blending malicious traffic into trusted SaaS egress.
  3. Deployment: Loader decrypts and injects one of the four RAT families, often via crypter services observed on the operator's machine.
  4. C2: Dynamic DNS (DuckDNS) and low-reputation TLD infrastructure (.xyz, .site).
  5. Persistence: Registry Run keys, scheduled tasks, and startup folder entries depending on the RAT family.
  6. Exfiltration: Browser credential stores, keystrokes, and stealer-log formatted archives uploaded to operator infrastructure.

Anti-Analysis Techniques

  • Payload staging on GitHub to defeat domain reputation controls
  • Crypter services to repack RAT binaries per campaign
  • AutoIt script obfuscation and WScript intermediate droppers
  • Dynamic DNS C2 to survive static domain takedowns
  • Geofenced lures targeting Colombian Spanish speakers only

IOC Analysis

The pulse contains 9 indicators across three types:

  • Domains (5): data-encoder.com, creainovada.xyz, consultanotificacionesjuridicas.site, simpmit.co, plus the malformed config.data artifact (likely a truncated C2 config field — treat as context, not a blockable domain).
  • Hostname (1): dccomicrat81.duckdns.org — dynamic DNS C2, consistent with DcRat operator naming conventions. Block DuckDNS subdomains at the resolver level only after confirming no legitimate business use; ideally alert on all *.duckdns.org resolution from endpoints.
  • URLs (2): http://creainovada.xyz/instructions/ and http://creainovada.xyz/instructions/Wscript.txt — active loader staging paths. The Wscript.txt artifact is a textbook Blind Eagle trick: a script payload served with a .txt extension to evade content-type inspection, then renamed and executed by the phishing attachment.

Operationalization Guidance for SOC Teams

  1. Block at the edge: Push all domains/hostnames to DNS sinkhole, web proxy, and EDR network block lists immediately.
  2. Retro-hunt DNS: Query the last 90 days of DNS/proxy logs for any resolution of these indicators — a single hit means a workstation reached staging or C2.
  3. Pivot on infrastructure: Use passive DNS (VirusTotal, SecurityTrails, Validin) to enumerate co-hosted domains on the same IPs; Blind Eagle rotates lures frequently and sibling domains are high-fidelity.
  4. Decode the loader: Any retrieved Wscript.txt or AutoIt script should be detonated in a sandbox (ANY.RUN, Triage) or decompiled with Exe2Aut / myAut2Exe for AutoIt binaries. Extract GitHub URLs from the decompiled source to enumerate the operator's repo inventory before takedown.
  5. GitHub telemetry: If your proxy logs GitHub raw/release downloads, hunt for raw.githubusercontent.com and github.com/*/releases/download requests from workstations that do not belong to developers — this is the highest-signal behavioral pivot in this campaign.

Detection Engineering

YAML
---
title: Blind Eagle AutoIt Loader Execution via WScript
description: Detects WScript/CScript executing script files with suspicious extensions or from user-writable staging paths, consistent with APT-C-36 (Blind Eagle) AutoIt/WScript loader delivery observed staging payloads from GitHub.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection_engine:
    Image|endswith:
      - '\wscript.exe'
      - '\cscript.exe'
  selection_args:
    CommandLine|contains:
      - '.txt'
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Public\'
      - '\Downloads\'
  filter_legit:
    CommandLine|contains:
      - '\Program Files\'
      - '\Windows\System32\'
  condition: selection_engine and selection_args and not filter_legit
falsepositives:
  - Rare legitimate administrative scripting from temp paths
level: high
tags:
  - attack.execution
  - attack.t1059.005
  - attack.t1059.007
  - attack.t1204.002
date: 2026/09/28
---
title: Non-Developer Process Downloading Payload from GitHub Raw or Releases
description: Detects script interpreters, Office apps, or RAT-stage tooling retrieving content from GitHub raw content or release asset URLs - Blind Eagle (APT-C-36) stages AsyncRAT, DcRat, Remcos and XWorm payloads in GitHub repositories.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection_url:
    CommandLine|contains:
      - 'raw.githubusercontent.com'
      - 'github.com'
      - 'objects.githubusercontent.com'
  selection_suspicious_parent:
    ParentImage|endswith:
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\winword.exe'
      - '\excel.exe'
      - '\rundll32.exe'
  condition: all of selection_*
falsepositives:
  - Developer workstations and software update mechanisms using GitHub releases; scope exclusions by parent process or user context
level: high
tags:
  - attack.command_and_control
  - attack.t1105
  - attack.t1071.001
date: 2026/09/28
---
title: AsyncRAT / DcRat Persistence via Registry Run Key or Scheduled Task
description: Detects persistence creation in Run keys or scheduled tasks pointing to user-writable paths, a common persistence pattern for AsyncRAT, DcRat, Remcos and XWorm deployed by APT-C-36 operators.
author: Security Arsenal Threat Intelligence
status: experimental
logsource:
  category: registry_set
  product: windows
detection:
  selection_key:
    TargetObject|contains:
      - '\CurrentVersion\Run\'
      - '\CurrentVersion\RunOnce\'
  selection_value:
    Details|contains:
      - '\AppData\'
      - '\Temp\'
      - '\Public\'
      - '\ProgramData\'
  filter_known_good:
    Details|contains:
      - 'OneDrive'
      - 'MicrosoftEdge'
      - 'Teams'
  condition: selection_key and selection_value and not filter_known_good
falsepositives:
  - Legitimate user-context applications registering autostart entries; tune against an enterprise software baseline
level: high
tags:
  - attack.persistence
  - attack.t1060
  - attack.t1547.001
date: 2026/09/28
KQL — Microsoft Sentinel / Defender
// Blind Eagle (APT-C-36) Hunt: IOC matching + behavioral pivots for GitHub-staged RAT loaders
// Microsoft Sentinel / Defender XDR - run over last 30 days

let BlindEagleIoCs = dynamic([
    "data-encoder.com",
    "creainovada.xyz",
    "consultanotificacionesjuridicas.site",
    "simpmit.co",
    "dccomicrat81.duckdns.org"
]);
let Lookback = 30d;

// Part 1: Direct IOC hits in network telemetry
let NetworkHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteUrl has_any (BlindEagleIoCs) or RemoteIP in (
    // enrich via your threat intel connector if IPs are resolved separately
    toscalar(DeviceNetworkEvents | where Timestamp > ago(Lookback)
        | where RemoteUrl has_any (BlindEagleIoCs) | distinct RemoteIP)
)
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
| extend MatchType = "Direct IOC Network Hit";

// Part 2: DNS resolution of DuckDNS dynamic DNS (DcRat C2 pattern)
let DuckDnsHits = DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where RemoteUrl endswith ".duckdns.org"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
| extend MatchType = "Dynamic DNS C2 Pattern";

// Part 3: Script interpreters pulling payloads from GitHub (loader staging behavior)
let GitHubStagerHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("wscript.exe", "cscript.exe", "mshta.exe", "powershell.exe", "cmd.exe", "rundll32.exe")
| where ProcessCommandLine has_any ("raw.githubusercontent.com", "github.com", "githubusercontent.com")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName
| extend MatchType = "GitHub Payload Staging via Script Interpreter";

// Part 4: WScript executing .txt-renamed scripts (Blind Eagle Wscript.txt tradecraft)
let TxtScriptHits = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where FileName in~ ("wscript.exe", "cscript.exe")
| where ProcessCommandLine has ".txt"
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName
| extend MatchType = "WScript Executing .txt Script";

union NetworkHits, DuckDnsHits, GitHubStagerHits, TxtScriptHits
| sort by Timestamp desc
PowerShell
# Blind Eagle (APT-C-36) Endpoint IOC & Artifact Hunt
# Checks for: campaign IOCs in DNS cache, Run-key persistence in user-writable paths,
# suspicious scheduled tasks, AutoIt/WScript staging artifacts, and active C2 connections.
# Run elevated on suspect endpoints. Review output before taking remediation action.

$Report = @()

Write-Host "[*] Checking DNS cache for campaign IOCs..." -ForegroundColor Cyan
$iocDomains = @("data-encoder.com","creainovada.xyz","consultanotificacionesjuridicas.site","simpmit.co","dccomicrat81.duckdns.org")
$dnsHits = Get-DnsClientCache | Where-Object { $e = $_.Entry; $iocDomains | Where-Object { $e -like "*$_*" } }
if ($dnsHits) { $Report += "[ALERT] DNS cache IOC hit:`n$($dnsHits | Out-String)" }

Write-Host "[*] Auditing Run / RunOnce persistence keys..." -ForegroundColor Cyan
$runKeys = @(
    "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
    "HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
    "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
    "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce"
)
foreach ($key in $runKeys) {
    if (Test-Path $key) {
        Get-ItemProperty $key | ForEach-Object {
            $_.PSObject.Properties | Where-Object {
                $_.Name -notmatch '^PS' -and $_.Value -match 'AppData|Temp|Public|ProgramData|\.txt|wscript|\.a3x'
            } | ForEach-Object {
                $Report += "[ALERT] Suspicious autostart: $key :: $($_.Name) = $($_.Value)"
            }
        }
    }
}

Write-Host "[*] Auditing scheduled tasks for user-path execution..." -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.State -ne 'Disabled' } | ForEach-Object {
    $actions = ($_.Actions | Out-String)
    if ($actions -match 'AppData|Temp\|wscript|cscript|\.a3x|powershell.*-enc') {
        $Report += "[ALERT] Suspicious scheduled task: $($_.TaskName) :: $actions"
    }
}

Write-Host "[*] Searching common staging directories for AutoIt/WScript artifacts..." -ForegroundColor Cyan
$stagingPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:PUBLIC","$env:USERPROFILE\Downloads")
foreach ($p in $stagingPaths) {
    Get-ChildItem $p -Recurse -Depth 2 -ErrorAction SilentlyContinue |
        Where-Object { $_.Extension -in '.a3x','.txt','.vbs','.js' -and $_.Length -gt 50KB } |
        ForEach-Object { $Report += "[REVIEW] Possible staged script: $($_.FullName) ($([math]::Round($_.Length/1KB)) KB)" }
}

Write-Host "[*] Checking active connections to dynamic DNS / known C2..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
    Where-Object { $_.RemotePort -in 6666,7777,8808,11778 -or $_.OwningProcess -in (Get-Process wscript,cscript,AutoIt3 -ErrorAction SilentlyContinue).Id } |
    ForEach-Object {
        $proc = (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName
        $Report += "[REVIEW] Connection: $proc ($($_.OwningProcess)) -> $($_.RemoteAddress):$($_.RemotePort)"
    }

Write-Host "`n===== HUNT RESULTS =====" -ForegroundColor Yellow
if ($Report.Count -eq 0) { Write-Host "[+] No Blind Eagle artifacts detected on this host." -ForegroundColor Green }
else { $Report | ForEach-Object { Write-Host "$_`n" -ForegroundColor Red } }

Response Priorities

Immediate (0–4 hours)

  • Block all pulse indicators at DNS resolver, secure web gateway, and EDR network layers: data-encoder.com, creainovada.xyz, consultanotificacionesjuridicas.site, simpmit.co, dccomicrat81.duckdns.org, and the full creainovada.xyz/instructions/ URL paths.
  • Enable alerting (not blanket blocking) on *.duckdns.org resolution to catch rotated DcRat/XWorm C2 without breaking legitimate DDNS use.
  • Run the KQL hunt across the last 30 days of telemetry; any GitHub-staging or WScript .txt hits trigger an immediate endpoint isolation and memory capture (RATs are largely fileless post-injection).
  • Sweep mail gateways for Colombian judicial-themed lures referencing "notificaciones jurídicas," "consulta," or similar legal-notification phrasing.

Within 24 Hours

  • Assume credential compromise on any host with an IOC hit. AsyncRAT, Remcos, and XWorm all harvest browser credential stores and session cookies. Force password resets and revoke active sessions/tokens (especially Microsoft 365 refresh tokens) for all users of affected machines.
  • Check whether harvested credentials from your environment appear in stealer log marketplaces — the operator's own compromise via stealer logs proves this data circulates rapidly. Engage your dark web monitoring capability for corporate domain matches.
  • Reimage confirmed-compromised endpoints rather than cleaning in place; multi-RAT deployment makes full artifact eradication unreliable.
  • Rotate any service accounts or VPN credentials used on affected hosts.

Within 1 Week

  • Restrict script interpreter abuse: deploy WDAC or AppLocker rules blocking WScript/CScript execution of files outside trusted extensions and paths; disable AutoIt (AutoIt3.exe) execution enterprise-wide unless business-justified.
  • Gate GitHub egress: for non-developer endpoints, proxy-restrict raw.githubusercontent.com and GitHub release-asset downloads, or at minimum log and alert on them. Blind Eagle's reliance on GitHub staging is a detection gift — use it.
  • Harden email controls for Spanish-language government-impersonation lures: attachment detonation for .txt, .vbs, .js, and compiled script executables.
  • Add the Sigma rules above to your detection pipeline and validate with Atomic Red Team tests for T1059.005/T1547.001.
  • Brief LATAM-facing business units on Blind Eagle's judicial-impersonation pretexts; this actor recycles lures across campaigns.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.