A live OTX pulse published by AlienVault/LevelBlue describes continued operator activity behind a GitHub-hosted loader ecosystem linked to APT-C-36, also tracked in overlapping reporting as Blind Eagle. The campaign focuses on Colombian government and juridical-themed phishing, using lookalike legal-notification domains, GitHub repositories for staging, crypter services, and commodity RATs rather than a single bespoke implant.
The operationally important point is the pipeline: phishing lure to staged script or loader, AutoIt or Windows Script Host execution, then deployment of one or more RAT families including AsyncRAT, DcRat, Remcos, and XWorm. The pulse also shows infrastructure analysis pivoting from GitHub commit metadata to an email address and then to stealer-log exposure of an operator workstation. That suggests an adversary using open platforms and criminal-market tooling with repeatable loader patterns rather than highly disciplined compartmentation.
The likely objective is durable remote access, credential and browser-data theft, surveillance of government users, and follow-on fraud or espionage. The presence of multiple RAT families means defenders should not overfit to one hash or one process name. Treat GitHub, raw content endpoints, DuckDNS, legal-themed Colombian domains, and script-host execution as a combined behavioral chain.
Threat Actor / Malware Profile
APT-C-36 / Blind Eagle is a financially and politically motivated threat cluster long associated with Colombian targeting, Spanish-language lures, juridical and banking themes, and commodity remote access trojans. This pulse reinforces that pattern with government targeting in Colombia and tags for Colombian phishing, GitHub loader activity, stealer logs, crypter services, and RAT deployment.
Distribution method: phishing emails and lure pages that mimic Colombian legal or judicial notifications, with domains such as consultanotificacionesjuridicas.site and simpmit.co. The reported infrastructure uses GitHub repositories to stage loaders and payloads, reducing the need for attacker-owned bulletproof hosting and blending malicious traffic with a legitimate developer platform.
Payload behavior: the loader can deliver AsyncRAT, DcRat, Remcos, XWorm, and an AutoIt backdoor. These families commonly provide remote shell, file transfer, keylogging, credential theft, screenshot capture, webcam or microphone access, process injection, and plugin-based expansion. Multiple RAT deployment can indicate fallback options, victim-specific tooling, or operator testing across crypter and loader services.
C2 communication: expected patterns include HTTP or HTTPS beaconing, DNS resolution of dynamic DNS such as dccomicrat81.duckdns.org, and outbound connections from script hosts, AutoIt, rundll32, regsvr32, or newly dropped executables. The listed URLs under creainovada.xyz, especially /instructions/ and /instructions/Wscript.txt, are high-value because they point to tasking or script-retrieval behavior.
Persistence: commodity RATs often use Run keys, scheduled tasks, startup folder shortcuts, WMI subscriptions, service creation, or masqueraded binaries in AppData, ProgramData, Temp, and user profile paths. Because the pulse lists loader staging rather than one persistence API, hunt broadly for autoruns created close to first execution and correlate with outbound RAT traffic.
Anti-analysis: crypter services, packed .NET payloads, AutoIt wrappers, GitHub staging, dynamic DNS, and file paths named to resemble instructions or notifications are likely. Expect string obfuscation, AMSI bypass attempts, sleep timers, sandbox checks, and payload retrieval only after a lure-specific precondition is met.
IOC Analysis
Indicator types in the pulse are domains, hostnames, and URLs. No IPs or file hashes are included in the sample, so network and process-behavior coverage matters more than static hash blocking.
High-confidence network indicators:
- data-encoder.com
- dccomicrat81.duckdns.org
- creainovada.xyz
- consultanotificacionesjuridicas.site
- simpmit.co
- http://creainovada.xyz/instructions/
- http://creainovada.xyz/instructions/Wscript.txt
Low-fidelity artifact: config.data is listed as a domain but is more likely a filename, configuration blob, or malformed extraction. Do not block it as a domain. Use it as a filename, URI fragment, registry value, and memory-string hunt term.
SOC operationalization: push domains and URLs to DNS sinkhole, secure web gateway, EDR network block, proxy categories, and firewall FQDN objects where supported. Add DuckDNS hostnames to dynamic-DNS alerting rather than assuming all DuckDNS is malicious. Ingest the URL paths into web proxy analytics because /instructions/ and Wscript.txt are more specific than the root domain. For tooling, use EDR for process and network correlation, DNS logs for resolution bursts, SWG logs for HTTP path retrieval, and sandbox detonation for GitHub or script artifacts. Decode obfuscated scripts with CyberChef or a controlled malware-analysis VM; unpack .NET RATs with dnSpy or de4dot in an isolated environment, and extract AutoIt strings only from a copy, never on a production host.
Detection Engineering
Use the following Sigma analytics as behavior-first coverage and tune to local parent-child norms.
---
title: Colombian Juridical Lure Script Host Retrieval of Wscript Tasking
id: 9f2c7a10-36ac-4c36-a001-otx20260928a
status: experimental
description: Detects Windows Script Host or command shell retrieval/execution patterns consistent with APT-C-36 GitHub loader tasking using creainovada.xyz /instructions/Wscript.txt and related legal-lure infrastructure.
author: Security Arsenal
references:
- https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader
date: 2026/09/28
modified: 2026/09/28
logsource:
category: process_creation
product: windows
level: high
detection:
selection_img:
Image|endswith:
- 'wscript.exe'
- 'cscript.exe'
- 'cmd.exe'
- 'powershell.exe'
- 'mshta.exe'
- 'rundll32.exe'
- 'regsvr32.exe'
- 'AutoIt3.exe'
- 'AutoIt3_x64.exe'
selection_cli:
CommandLine|contains:
- 'creainovada.xyz'
- '/instructions/'
- 'Wscript.txt'
- 'consultanotificacionesjuridicas.site'
- 'simpmit.co'
- 'data-encoder.com'
- 'duckdns.org'
- 'github.com'
- 'raw.githubusercontent.com'
condition: selection_img and 1 of selection_cli
falsepositives:
- Software deployment scripts using GitHub raw content in managed enterprise repos
- Admin automation using AutoIt with explicit change tickets
fields:
- Image
- CommandLine
- ParentImage
- User
- ComputerName
tags:
- attack.initial_access
- attack.execution
- attack.t1059
- attack.t1105
- attack.command_and_control
- attack.t1071.001
---
title: Commodity RAT Loader Follow-On Execution from User Writable Paths
id: 9f2c7a10-36ac-4c36-a001-otx20260928b
status: experimental
description: Detects execution of AsyncRAT, DcRat, Remcos, XWorm, or AutoIt loader artifacts from AppData, ProgramData, Temp, Startup, or recently staged GitHub downloads followed by network-capable LOLBin activity.
author: Security Arsenal
references:
- https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader
date: 2026/09/28
modified: 2026/09/28
logsource:
category: process_creation
product: windows
level: high
detection:
selection_path:
Image|contains:
- 'AppData'
- 'ProgramData'
- 'Temp'
- 'Startup'
- 'Downloads'
selection_names:
CommandLine|contains:
- 'asyncrat'
- 'dcrat'
- 'remcos'
- 'xworm'
- 'config.data'
- 'data-encoder'
- 'dccomicrat81'
selection_lolbin:
ParentImage|endswith:
- 'wscript.exe'
- 'cscript.exe'
- 'mshta.exe'
- 'AutoIt3.exe'
- 'AutoIt3_x64.exe'
- 'powershell.exe'
condition: selection_path and (selection_names or selection_lolbin)
falsepositives:
- User-installed legitimate tools in Downloads
- IT support remote tools, which should be allowlisted by signer and path
fields:
- Image
- ParentImage
- CommandLine
- IntegrityLevel
- Hashes
tags:
- attack.execution
- attack.persistence
- attack.t1068
- attack.t1543
- attack.t1059
- attack.t1105
---
title: Network Egress to APT-C-36 Dynamic DNS or Colombian Legal-Lure Domains
id: 9f2c7a10-36ac-4c36-a001-otx20260928c
status: experimental
description: Detects DNS or network egress from endpoint processes to listed APT-C-36 loader, C2, and lure domains including DuckDNS and creainovada.xyz paths.
author: Security Arsenal
references:
- https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader
date: 2026/09/28
modified: 2026/09/28
logsource:
category: network_connection
product: windows
level: critical
detection:
selection_dest:
DestinationHostname|contains:
- 'data-encoder.com'
- 'dccomicrat81.duckdns.org'
- 'creainovada.xyz'
- 'consultanotificacionesjuridicas.site'
- 'simpmit.co'
selection_proc:
Image|endswith:
- 'wscript.exe'
- 'cscript.exe'
- 'AutoIt3.exe'
- 'AutoIt3_x64.exe'
- 'powershell.exe'
- 'rundll32.exe'
- 'regsvr32.exe'
- 'mshta.exe'
condition: selection_dest and selection_proc
falsepositives:
- Rare, but possible researcher browsing from corporate endpoints; scope to endpoints and egress processes
fields:
- Image
- DestinationHostname
- DestinationIp
- DestinationPort
- User
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1568.002
- attack.t1105
Hunt across process and network telemetry with one correlated query.
let iocs = dynamic(['data-encoder.com','dccomicrat81.duckdns.org','creainovada.xyz','consultanotificacionesjuridicas.site','simpmit.co']);
let procs = dynamic(['wscript.exe','cscript.exe','mshta.exe','AutoIt3.exe','AutoIt3_x64.exe','powershell.exe','rundll32.exe','regsvr32.exe']);
let net = DeviceNetworkEvents
| where Timestamp > ago(14d)
| where RemoteUrl has_any (iocs) or RemoteUrl contains 'duckdns.org' or RemoteUrl contains 'creainovada.xyz'
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, ActionType;
let proc = DeviceProcessEvents
| where Timestamp > ago(14d)
| where FileName in~ (procs)
or ProcessCommandLine has_any (dynamic(['asyncrat','dcrat','remcos','xworm','config.data','Wscript.txt','/instructions/','github.com','raw.githubusercontent.com','dccomicrat81']))
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256;
net
| join kind=inner proc on DeviceName
| where abs((Timestamp - Timestamp1)/1s) < 900
| project NetTime=Timestamp, ProcTime=Timestamp1, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, FolderPath, SHA256
| order by ProcTime desc;
Run this read-only endpoint hunt to collect likely persistence, script, and network artifacts without changing system state.
$ErrorActionPreference = 'SilentlyContinue'
$domains = @('data-encoder.com','dccomicrat81.duckdns.org','creainovada.xyz','consultanotificacionesjuridicas.site','simpmit.co')
$terms = @('asyncrat','dcrat','remcos','xworm','config.data','Wscript.txt','/instructions/','dccomicrat81','data-encoder','creainovada')
$out = Join-Path $env:TEMP ('aptc36_hunt_' + (Get-Date -Format 'yyyyMMdd_HHmmss') + '.csv')
$rows = New-Object System.Collections.Generic.List[object]
foreach ($path in @('HKCU:\Software\Microsoft\Windows\CurrentVersion\Run','HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce','HKLM:\Software\Microsoft\Windows\CurrentVersion\Run','HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce')) {
if (Test-Path $path) {
Get-ItemProperty $path | ForEach-Object {
$_.PSObject.Properties | Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object {
$line = ($_.Name + ' = ' + $_.Value)
foreach ($t in $terms) { if ($line -match [regex]::Escape($t)) { $rows.Add([pscustomobject]@{Type='Autorun'; Path=$path; Evidence=$line; Host=$env:COMPUTERNAME; Time=(Get-Date)}) } }
}
}
}
}
Get-ScheduledTask | ForEach-Object {
$taskText = ($_ | Out-String)
foreach ($t in $terms) { if ($taskText -match [regex]::Escape($t)) { $rows.Add([pscustomobject]@{Type='ScheduledTask'; Path=$_.TaskPath + $_.TaskName; Evidence=($_.Actions | Out-String); Host=$env:COMPUTERNAME; Time=(Get-Date)}) } }
}
Get-NetTCPConnection | Where-Object { $_.State -eq 'Established' } | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess
$name = if ($p) { $p.ProcessName } else { '' }
$cmd = if ($p) { (Get-CimInstance Win32_Process -Filter "ProcessId=$($_.OwningProcess)").CommandLine } else { '' }
foreach ($t in $terms) { if (($name + ' ' + $cmd) -match [regex]::Escape($t)) { $rows.Add([pscustomobject]@{Type='Network'; Path=$name; Evidence=($_.RemoteAddress + ':' + $_.RemotePort + ' | ' + $cmd); Host=$env:COMPUTERNAME; Time=(Get-Date)}) } }
}
Get-DnsClientCache | Where-Object { $_.Entry -match ($domains -join '|') } | ForEach-Object {
$rows.Add([pscustomobject]@{Type='DnsCache'; Path=$_.Entry; Evidence=($_.Data | Out-String); Host=$env:COMPUTERNAME; Time=(Get-Date)})
}
$rows | Sort-Object Type, Path | Export-Csv -NoTypeInformation -Path $out
Write-Host ('Wrote ' + $rows.Count + ' findings to ' + $out)
$rows | Format-Table -AutoSize
Response Priorities
Immediate: block the listed domains, hostname, and full URLs at DNS, proxy, SWG, EDR network control, and mail gateway. Alert on any resolution of dccomicrat81.duckdns.org and any retrieval of /instructions/ or Wscript.txt. Hunt for wscript, cscript, mshta, AutoIt3, powershell, rundll32, and regsvr32 spawning or retrieving content from GitHub, legal-themed Colombian domains, or user-writable paths. Isolate endpoints with matching network events and capture process trees, autoruns, DNS cache, proxy logs, and memory if RAT execution is suspected.
24h: because AsyncRAT, Remcos, XWorm, and DcRat commonly steal browser credentials, cookies, tokens, mail data, and saved VPN or RDP secrets, force password resets and revoke sessions for affected users and any accounts used on the same host. Prioritize government email, identity providers, cloud consoles, banking or payment portals, and service accounts. Review MFA fatigue signs, impossible travel, OAuth grants, inbox rules, and new device enrollments. If stealer-log exposure is suspected, assume credentials were resold and monitor for credential stuffing against external portals.
1 week: harden the architecture against this loader chain. Restrict or alert on user browsing to raw GitHub content where not required, apply proxy inspection to GitHub and dynamic DNS categories, block script hosts for standard users via WDAC or AppLocker, constrain Office and browser child processes, disable AutoIt where not business approved, and require code-signing for scripts. Add detections for Spanish juridical lure themes, newly registered Colombian legal domains, and commodity RAT persistence. Build a tabletop around a Colombian government phishing lure that ends in multi-RAT deployment and credential replay.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.