BlindEagle Targets Colombian Government Agency with Caminho and DCRAT
A spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism was discovered in September 2025. The attack, attributed to BlindEagle, utilized a compromised email account within the organization to bypass security controls. The campaign employed a sophisticated multi-layer attack chain, including a fake web portal, nested JavaScript and PowerShell scripts, steganography, and the deployment of Caminho as a downloader for DCRAT. The attack leveraged legal-themed lures, in-memory execution, and abuse of legitimate services like Discord. BlindEagle's evolution in tactics and use of new tools like Caminho demonstrates their ongoing threat to Colombian institutions.
Pulse ID: 69421a1f3d6e9eac9a0ce057
Pulse Link: https://otx.alienvault.com/pulse/69421a1f3d6e9eac9a0ce057
Pulse Author: AlienVault
Created: 2025-12-17 02:49:03
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #Discord #Email #Government #ICS #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RCE #SpearPhishing #Steganography #bot #AlienVault