🚨 Blind Eagle Exposed
Researchers uncovered Blind Eagle’s GitHub infrastructure, revealing malware loaders, multiple RAT families, and an organized setup built for rapid deployment and espionage.
🔗 https://t.co/DaqOCOom5o
#CyberSecurity#APT#ThreatIntel
A successful breach of the Blind Eagle-linked malware operation exposed a full arsenal: AsyncRAT, Remcos, XWorm RATs; phishing kits using judicial and traffic-related lures; GitHub staging repos; and stealthy loaders abusing AutoIt3, PowerShell & InstallUtil.exe. This meltdown reveals how attackers’ infrastructures rely on modular tools, fake official notices, and embedded archive tricks. For defenders: tighten detection for scripts, suspicious archive attachments, and raw-hosting URLs. #Security #Malware #BlindEagle #Phishing #RATs #CyberThreat
#Malware #Security #BlindEagle #Phishing #RATs #CyberThreat
https://t.co/FJ9uhfcqe6
A malware investigation has exposed the tools and infrastructure used by suspected operators behind a Blind Eagle-linked campaign targeting Colombia and the wider region.
The break came after an apparent attacker workstation was infected by a separate information-stealing program, leaving a record of its activity.
The operation used phishing emails impersonating Colombian judicial bodies and traffic authorities.
Victims were directed to password-protected archives, a technique also seen in recent password-protected archive attacks that can reduce automated email scanning and delay detection.
LevelBlue said in a report shared with Cyber Security News (CSN) that its analysts traced a GitHub commit email address to a stolen-data log.
The recovered material showed browser history, local folders and credentials from a device associated with the campaign’s operational trail.
🚨 [THREAT INTELLIGENCE] — A SUSPECTED BLIND EAGLE OPERATOR WAS EXPOSED AFTER THEIR OWN MALWARE-BUILDING WORKSTATION WAS INFECTED BY AN UNRELATED INFOSTEALER
The leaked machine revealed RAT collections, phishing templates, bulk-email tooling, commercial crypters, hosting infrastructure and campaign artifacts — effectively exposing part of the attacker’s production pipeline.
CyberSignal Priority: 🔴 VERY HIGH
📅 Research: August 28–31, 2026
👤 Blind Eagle / APT-C-36-linked activity
🎯 Colombia · Latin America
🏷️ OPSEC Failure · Infostealer · RAT · Phishing · GitHub Abuse
Sometimes the most valuable threat intelligence does not come from compromising an attacker.
It comes from another criminal compromising them first.
### 🔎 What happened
LevelBlue SpiderLabs was investigating a GitHub account used to stage components of a malicious loader.
Researchers noticed something simple:
GitHub commit metadata exposed an email address associated with the account.
That email was then found inside a leaked infostealer dataset.
Additional compromise intelligence indicated the associated computer — hostname:
**“Ghost”**
— had itself been infected by an information stealer.
The recovered stealer log provided visibility into local files, browsing activity and operational artifacts stored on that machine.
### ⚔️ Investigation chain
Malicious GitHub staging account
↓
Commit metadata exposes email
↓
Email found in stealer-log collection
↓
Independent infection evidence confirms compromised workstation
↓
Underlying stealer archive recovered
↓
Local directory structure examined
↓
RAT-building folders discovered
↓
Phishing templates identified
↓
Bulk-email infrastructure reconstructed
↓
Crypter purchases + hosting activity exposed
### 🦠 What researchers found
The workstation contained folders associated with multiple RAT families.
Researchers also found:
phishing templates
malware builds
sender identities
hosting information
delivery infrastructure
bulk-email software
commercial crypters
cloud/file-storage services.
One Remcos-related directory contained numerous system-information files apparently associated with other compromised hosts.
The environment looked less like:
“someone experimenting with malware”
and more like:
**a small cybercrime production environment.**
### 🎣 The phishing side
Stored templates impersonated Colombian government and judicial institutions.
Themes included:
judicial notifications
traffic violations
official-looking legal communications.
Researchers also found evidence of attacker efforts to make sender identities visually credible.
The workflow appears to have been:
create lure
↓
create institutional-looking identity
↓
prepare phishing domain
↓
configure email delivery
↓
package malware
↓
send campaign.
### 📧 Delivery infrastructure
The workstation contained SendBlaster configured with an external SMTP relay.
Browser history also showed activity involving services such as:
Brevo
Mailrelay
HubSpot
DreamHost
HostGator
Firebase.
GitHub was therefore only ONE layer of the infrastructure.
### 🥷 Evasion shopping
Researchers found searches and activity involving commercial protection/crypter services including:
FUD Crypter
MI6 Crypter
PolyCrypt
Cassandra Protector.
Evidence indicated at least one paid subscription had been purchased.
That matters because it shows deliberate investment in:
**reducing malware detection.**
### 🎯 What is affected
Blind Eagle has historically focused heavily on Latin America, particularly Colombian organizations and users.
The investigation connects the recovered environment to infrastructure and tradecraft consistent with Blind Eagle operations.
### ⚠️ Important caveat
This does NOT prove that every artifact on the infected machine belongs exclusively to Blind Eagle.
LevelBlue explicitly treats some evidence as supporting clues rather than absolute attribution.
An attacker workstation can contain:
old malware
research tools
third-party tools
unrelated infrastructure.
Attribution therefore comes from the convergence of multiple artifacts — not one folder or email address.
### 🛡️ Defender action
Organizations in Latin America should watch for:
government/judicial phishing themes
password-protected archives
VBScript/PowerShell execution
InstallUtil abuse
AsyncRAT/Remcos-style activity
DuckDNS C2
malware staged through GitHub or cloud storage.
And CTI teams should remember:
Git commit metadata
developer usernames
certificate metadata
stealer logs
passive DNS
hosting history
can expose infrastructure relationships malware analysis alone may miss.
### 🧠 CyberSignal insight
**Threat actors suffer from the same endpoint-security failures as everyone else. One stolen browser profile can expose an entire criminal development pipeline.**
Sources: LevelBlue SpiderLabs · independent compromise intelligence
It turns out this goop someone sent me in a DM was state-sponsored malware designed to perform espionage on select groups on individuals in South America
This malware campaign was attributed to APT-C-36
Silly government written malware haha bonk bonk haha
A Git commit on that account leaked the #BlindEagle Group’s email.
Researchers matched the same address in an ALIEN TXTBASE stealer log and Hudson Rock data.
That machine contained the operator’s working set:
RAT build folders, phishing templates, SendBlaster logs of test messages sent back to the same operational mailbox, and bookmarks for bulk-mail/SMTP services.
GitHub commit metadata tied cabeto850128 to a stolen email, exposing a compromised workstation and files that mapped a Blind Eagle-style stack of RATs, phishing kits, crypters, and cloud infrastructure. #BlindEagle#AsyncRAT#GitHub
https://t.co/GprPiSnUNn
LevelBlue and Emmanuel C. collaboratively analyzed Blind Eagle's GitHub loader, detailing infrastructure findings and ongoing evolution of the tool. https://t.co/9aunaN3S0h
Dopo una settimana di analisi abbiamo ricostruito quanto accaduto durante lo scorso week-end ai numerosi possessori di #iPhone con iOS 16 che hanno subito un attacco #0click sull'App #Whatsapp.
Abbiamo ricevuto infatti varie segnalazioni di utenti di iPhone con #iOS16 che hanno segnalato il loro account WhatsApp "clonato" da terzi che sono stati in grado di leggere i messaggi e inviare ai propri contatti richieste fraudolente di pagamento.
Non si tratta di un semplice #ghostpairing, tanto che le vittime non vedono dispositivi collegati al proprio account, ma di un attacco tramite CVE-2025-43300, possibilmente in combinazione con il #CVE 2025-55177, che sfrutta l'elaborazione delle immagini ricevute in chat per infettare i dispositivi e attivare un #resync continuo sulla sessione principale: in sostanza, è impossibile cacciare fuori gli attaccanti fin tanto che l'App infetta è attiva.
Nel post @forensersrl e con maggiori dettagli nell'articolo sul sito web trovate spiegato cosa è successo, come è potuto accadere come ci si può difendere: onore al merito del team #Forenser che ormai sulla ricerca e analisi di malware sta raggiungendo altissimi livelli di precisione, grazie anche ai diversi casi gestiti negli ultimi anni su infezioni tra le quali #Paragon / #Graphite / #Pegasus e vari altri #trojan e #captatori piuttosto complicati da rilevare e analizzare.
🔴 “J’étais seul dans ma chambre et j’ai dérapé” : le profil du hacker HexDex se précise.
Selon Le Monde, derrière ce pseudonyme se cacherait Faouzi C., 21 ans, maraîcher vendéen vivant à Aizenay, sans compétence avancée revendiquée en cybersécurité.
Son mode opératoire ? Rechercher des identifiants fuités, tester des accès compromis, repérer des failles web, puis utiliser un bot russe ou ukrainien ainsi que l’intelligence artificielle pour générer des scripts capables d’extraire des bases de données.
Selon l’enquête, les policiers seraient remontés jusqu’à lui grâce aux données récupérées après la saisie de BreachForums. Avant cette affaire, Faouzi C. était déjà connu de la justice pour sa participation présumée à un guet-apens lié au sulfureux forum Coco, où un homme pensait rencontrer une mineure de 15 ans.
HexDex est soupçonné d’avoir visé plus de 90 organismes : ministères, universités, syndicats, fédérations sportives, Darty, Florajet ou encore des fichiers sensibles liés aux détenteurs d’armes.
Le portrait qui se dessine est moins celui d’un “génie du hacking” que d’un jeune homme isolé, en quête de buzz, d’adrénaline et de reconnaissance derrière un personnage devenu incontrôlable.
В марте хакеры ФСБ провели рассылку писем со ссылкой, переход по которой мог привести к полной компрометации устройства.
Я был первый, кто обратил внимание на эти письма, проанализировал их, а также отобрал у ФСБ их домен.
Тред с подробностями и советами:
El gran dilema será el software electoral. Intenté evitarlo mediante una auditoría que ayudara a neutralizar cualquier narrativa de fraude o manipulación, pero no lo permitieron. Por eso, se merecen todo lo que pasará.
New C2 infrastructure and lures detected associated with #Coruna and #DarkSword malware. Threat actors are using fake crypto reward scam web pages to deliver malicious URLs and RCE exploits to iOS users. Details at: https://t.co/YCo7obJ4R6
Candidato @LuisGMurillo, ofrecí donar esta auditoría para contribuir al fortalecimiento de la democracia de mi país, haciendo de la tecnología una herramienta que ayude a garantizar la transparencia en la decisión de las personas en las urnas, sin importar cuál sea la voluntad popular, porque mi trabajo no es político, es 100% técnico.
Así que, actuando bajo un mandato de veeduría técnica unificada, si los demás candidatos también deciden depositar su confianza en mí y se unen a esta iniciativa de delegación conjunta, estoy listo para auditar no solo el código fuente de los softwares electorales, sino también para aportar mis conocimientos y experiencia al blindaje de toda la infraestructura tecnológica de las #Elecciones2026.
La democracia del Siglo XXI también se garantiza con ciberseguridad, porque la transparencia electoral no debe ser confidencial, debe estar siempre a la vista de toda la ciudadanía.
@IvanCepedaCast@ClaudiaLopez@Santibotero2026@ABDELAESPRIELLA@MauricioLizcano@migueluribel@SondraMacol@RoyBarreras@carlosecaicedo@GralMatamoro@PalomaValenciaL@sergio_fajardo@Registraduria@CNE_COLOMBIA@DefensoriaCol@MOEColombia@PGN_COL
Since 2021, North Korean (#DPRK) IT workers have built a sprawling ecosystem of synthetic developer personas complete with AI‑generated photos, overlapping #GitHub repositories, and reusable portfolio sites. Our investigation uncovered a single GitHub account (cybersage14) that switched identities from “Nicolas Sammaritano” (Argentina) to “Caddo Smith” (Texas) while keeping the same technical profile. This is not isolated fraud; it is a structured, labor‑enabled access model designed to infiltrate global companies and evade sanctions. #InsiderThreat
La Dijin de la Policía y la Fiscalía desmantelaron una red dedicada al fraude masivo con malware y “email spoofing”. En total fueron 5 capturados en Medellín, Barranquilla y Malambo.
La banda habría afectado a más de 16 empresas desde 2023, con pérdidas superiores a $500 millones, usando correos falsos de entidades oficiales para instalar malware y tomar control de sistemas financieros. #VocesySonidos