« All threats

APT groupMITRE G0099

APT-C-36

Also known as: aguilaciega, apt-q-98, blind eagle, tag-144

[APT-C-36](https://attack.mitre.org/groups/G0099) is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. [APT-C-36](https://attack.mitre.org/groups/G0099) has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.(Citation: QiAnXin APT-C-36 Feb2019)(Citation: Kaspersky BlindEagle AUG 2024)(Citation: Check Point Blind Eagle MAR 2025)(Citation: Recorded Future TAG-144 AUG 2025)

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Execution Prevention (8 techniques covered)
  2. Restrict Web-Based Content (7 techniques covered)
  3. Behavior Prevention on Endpoint (7 techniques covered)
  4. User Training (6 techniques covered)
  5. Audit (6 techniques covered)
  6. Antivirus/Antimalware (6 techniques covered)
  7. Network Intrusion Prevention (5 techniques covered)
  8. User Account Management (4 techniques covered)

MITRE ATT&CK techniques

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.