APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection.5 APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.6
group
APT-C-36 G0099
- Created
- 5 May 2020
- Last modified
- 31 July 2026
- Aliases
- APT-C-36 · Blind Eagle · TAG-144 · AguilaCiega · APT-Q-98
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0099
APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.7889
APT-C-36 has used encoded and obfuscated files, images, and executables.11
APT-C-36 has used junk characters to obfuscate malicious scripts.12
APT-C-36 has disguised its scheduled tasks as those used by Google.13
APT-C-36 has disguised malicious executables to appear as legitimate files.14
Standing G0099
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
74th percentile · 74% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
52nd percentile · 52% of 176 ATT&CK groups have this many tactics spanned or fewer.
81st percentile · 81% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
14th percentile · 86% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0099
1003 distinct rules cover the 38 techniques recorded for this group. The 1203 technique-to-rule mappings resolve to 1003 distinct rules, because one rule can cover several techniques. 680 Sigma · 323 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org