BlindEagle Targets Colombian Government Agency with Caminho and DCRAT
A spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism was discovered in September 2025. The attack, attributed to BlindEagle, utilized a compromised email account within the organization to bypass security controls. The campaign employed a sophisticated multi-layer attack chain, including a fake web portal, nested JavaScript and PowerShell scripts, steganography, and the deployment of Caminho as a downloader for DCRAT. The attack leveraged legal-themed lures, in-memory execution, and abuse of legitimate services like Discord. BlindEagle's evolution in tactics and use of new tools like Caminho demonstrates their ongoing threat to Colombian institutions.
AI Analysis
Technical Summary
The BlindEagle threat actor launched a spear phishing campaign in September 2025 targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attackers leveraged a compromised internal email account to bypass perimeter defenses and deliver a sophisticated multi-stage attack. The initial vector involved a fake web portal designed to lure victims with legal-themed content, exploiting user trust and social engineering. The payload delivery utilized nested JavaScript and PowerShell scripts, which executed in-memory to evade detection by traditional antivirus and endpoint security solutions. Steganography was employed to conceal malicious code within seemingly benign files, complicating forensic analysis. The downloader Caminho was used to fetch and deploy DCRAT, a remote access trojan capable of persistent control and data exfiltration. The campaign also abused legitimate services such as Discord for command and control communications, blending malicious traffic with normal network activity. The attack chain incorporated multiple MITRE ATT&CK techniques including T1053.005 (Scheduled Task), T1047 (Windows Management Instrumentation), T1059.007 (PowerShell), T1566.001 (Spear Phishing), and others related to defense evasion, persistence, and credential access. This evolution in tactics and tooling highlights BlindEagle’s continued focus on Colombian institutions and their ability to adapt to security improvements. No known exploits are publicly reported, and the attack requires initial user interaction through phishing. The overall campaign demonstrates a medium severity threat with significant impact on confidentiality and integrity of targeted systems.
Potential Impact
For European organizations, the direct impact may be limited due to the specific targeting of Colombian government entities. However, the tactics and tools used by BlindEagle could be adapted or repurposed against European government agencies or critical infrastructure with similar IT environments. The use of compromised internal accounts to bypass security controls and the abuse of legitimate services like Discord for command and control pose risks to confidentiality, enabling data theft or espionage. The in-memory execution and steganography techniques complicate detection and response, potentially allowing prolonged undetected access. European organizations involved in diplomatic, trade, or governmental relations with Colombia or Latin America could face indirect risks if the threat actor expands targeting. Additionally, the campaign underscores the importance of securing email systems, monitoring for insider threats, and controlling the use of non-traditional communication platforms within sensitive networks. The medium severity rating reflects moderate ease of exploitation but significant potential damage if successful.
Mitigation Recommendations
1. Implement advanced email security solutions with anomaly detection to identify compromised internal accounts and spear phishing attempts, including monitoring for unusual sending patterns and content. 2. Enforce strict multi-factor authentication (MFA) on all email and critical system accounts to reduce the risk of account compromise. 3. Deploy endpoint detection and response (EDR) tools capable of detecting in-memory execution, nested scripting, and steganographic payloads. 4. Restrict or monitor the use of unauthorized communication platforms such as Discord within corporate and government networks, especially for sensitive or classified environments. 5. Conduct regular user awareness training focused on spear phishing and social engineering, emphasizing the risks of legal-themed lures and suspicious web portals. 6. Utilize network segmentation and least privilege principles to limit lateral movement and access to critical systems. 7. Monitor scheduled tasks, WMI activity, and PowerShell execution logs for suspicious behavior indicative of attacker persistence or execution techniques. 8. Establish incident response playbooks tailored to multi-stage, stealthy intrusions involving advanced malware and legitimate service abuse. 9. Collaborate with threat intelligence providers to stay updated on BlindEagle tactics and indicators of compromise (IOCs). 10. Conduct regular security audits and penetration testing to identify and remediate gaps that could be exploited by similar threat actors.
Affected Countries
Colombia, Spain, Germany, France, United Kingdom, Belgium, Netherlands
Indicators of Compromise
- ip: 181.206.158.190
- ip: 74.124.24.240
- domain: startmenuexperiencehost.ydns.eu
- ip: 103.20.102.151
- ip: 103.236.70.158
- ip: 191.93.118.254
- hash: 4284e99939cebf40b8699bed31c82fd6
- hash: 961ebce4327b18b39630bfc4edb7ca34
- hash: 9799484e3942a6692be69aec1093cb6c
- hash: 97adb364d695588221d0647676b8e565
- hash: bbb99dfd9bf3a2638e2e9d13693c731c
- hash: c98eb5fcddf0763c7676c99c285f6e80
- hash: d80237d48e1bbc2fdda741cbf006851a
- hash: 21e95fed5fc5c4a10fafbc3882768cce1f6cd7af
- hash: 38b0e360d58d4ddb17c0a2c4d97909be43a3adc0
- hash: 3983a5b4839598ba494995212544da05087b811b
- hash: 3ab2aa4e9a7a8abcf1ea42b51152f6bb15a1b3c5
- hash: 4397920a0b08a31284aff74a0bed9215d5787852
- hash: 722a4932576734a08595c7196d87395e6ec653d7
- hash: b3fb8a805d3acc2eda39a83a14e2a73e8b244cf4
- hash: 03548c9fad49820c52ff497f90232f68e044958027f330c2c51c80f545944fc1
- hash: 08a5d0d8ec398acc707bb26cb3d8ee2187f8c33a3cbdee641262cfc3aed1e91d
- hash: 3ef2cf8f65a9a6f4955ecd0292af0cd68e65864907d07543c416ab28a2acfa6d
- hash: 8f3dc1649150961e2bac40d8dabe5be160306bcaaa69ebe040d8d6e634987829
- hash: c208d8d0493c60f14172acb4549dcb394d2b92d30bcae4880e66df3c3a7100e4
- hash: d0fe6555bc72a7a45a836ea137850e6e687998eb1c4465b8ad1fb6119ff882ab
- hash: d139bfe642f3080b461677f55768fac1ae1344e529a57732cc740b23e104bff0
- hash: e7666af17732e9a3954f6308bc52866b937ac67099faa212518d5592baca5d44
- ip: 103.186.108.212
- ip: 103.20.102.130
- ip: 178.16.54.45
- ip: 179.13.11.235
- ip: 179.13.4.196
- ip: 181.131.217.135
- ip: 181.235.3.119
- ip: 185.18.222.5
- ip: 191.91.178.101
- ip: 203.104.42.92
- ip: 45.153.34.67
BlindEagle Targets Colombian Government Agency with Caminho and DCRAT
Description
A spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism was discovered in September 2025. The attack, attributed to BlindEagle, utilized a compromised email account within the organization to bypass security controls. The campaign employed a sophisticated multi-layer attack chain, including a fake web portal, nested JavaScript and PowerShell scripts, steganography, and the deployment of Caminho as a downloader for DCRAT. The attack leveraged legal-themed lures, in-memory execution, and abuse of legitimate services like Discord. BlindEagle's evolution in tactics and use of new tools like Caminho demonstrates their ongoing threat to Colombian institutions.
AI-Powered Analysis
Technical Analysis
The BlindEagle threat actor launched a spear phishing campaign in September 2025 targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attackers leveraged a compromised internal email account to bypass perimeter defenses and deliver a sophisticated multi-stage attack. The initial vector involved a fake web portal designed to lure victims with legal-themed content, exploiting user trust and social engineering. The payload delivery utilized nested JavaScript and PowerShell scripts, which executed in-memory to evade detection by traditional antivirus and endpoint security solutions. Steganography was employed to conceal malicious code within seemingly benign files, complicating forensic analysis. The downloader Caminho was used to fetch and deploy DCRAT, a remote access trojan capable of persistent control and data exfiltration. The campaign also abused legitimate services such as Discord for command and control communications, blending malicious traffic with normal network activity. The attack chain incorporated multiple MITRE ATT&CK techniques including T1053.005 (Scheduled Task), T1047 (Windows Management Instrumentation), T1059.007 (PowerShell), T1566.001 (Spear Phishing), and others related to defense evasion, persistence, and credential access. This evolution in tactics and tooling highlights BlindEagle’s continued focus on Colombian institutions and their ability to adapt to security improvements. No known exploits are publicly reported, and the attack requires initial user interaction through phishing. The overall campaign demonstrates a medium severity threat with significant impact on confidentiality and integrity of targeted systems.
Potential Impact
For European organizations, the direct impact may be limited due to the specific targeting of Colombian government entities. However, the tactics and tools used by BlindEagle could be adapted or repurposed against European government agencies or critical infrastructure with similar IT environments. The use of compromised internal accounts to bypass security controls and the abuse of legitimate services like Discord for command and control pose risks to confidentiality, enabling data theft or espionage. The in-memory execution and steganography techniques complicate detection and response, potentially allowing prolonged undetected access. European organizations involved in diplomatic, trade, or governmental relations with Colombia or Latin America could face indirect risks if the threat actor expands targeting. Additionally, the campaign underscores the importance of securing email systems, monitoring for insider threats, and controlling the use of non-traditional communication platforms within sensitive networks. The medium severity rating reflects moderate ease of exploitation but significant potential damage if successful.
Mitigation Recommendations
1. Implement advanced email security solutions with anomaly detection to identify compromised internal accounts and spear phishing attempts, including monitoring for unusual sending patterns and content. 2. Enforce strict multi-factor authentication (MFA) on all email and critical system accounts to reduce the risk of account compromise. 3. Deploy endpoint detection and response (EDR) tools capable of detecting in-memory execution, nested scripting, and steganographic payloads. 4. Restrict or monitor the use of unauthorized communication platforms such as Discord within corporate and government networks, especially for sensitive or classified environments. 5. Conduct regular user awareness training focused on spear phishing and social engineering, emphasizing the risks of legal-themed lures and suspicious web portals. 6. Utilize network segmentation and least privilege principles to limit lateral movement and access to critical systems. 7. Monitor scheduled tasks, WMI activity, and PowerShell execution logs for suspicious behavior indicative of attacker persistence or execution techniques. 8. Establish incident response playbooks tailored to multi-stage, stealthy intrusions involving advanced malware and legitimate service abuse. 9. Collaborate with threat intelligence providers to stay updated on BlindEagle tactics and indicators of compromise (IOCs). 10. Conduct regular security audits and penetration testing to identify and remediate gaps that could be exploited by similar threat actors.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/blindeagle-targets-colombian-government-agency-caminho-and-dcrat"]
- Adversary
- BlindEagle
- Pulse Id
- 69421a1f3d6e9eac9a0ce057
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip181.206.158.190 | — | |
ip74.124.24.240 | — | |
ip103.20.102.151 | — | |
ip103.236.70.158 | — | |
ip191.93.118.254 | — | |
ip103.186.108.212 | — | |
ip103.20.102.130 | — | |
ip178.16.54.45 | — | |
ip179.13.11.235 | — | |
ip179.13.4.196 | — | |
ip181.131.217.135 | — | |
ip181.235.3.119 | — | |
ip185.18.222.5 | — | |
ip191.91.178.101 | — | |
ip203.104.42.92 | — | |
ip45.153.34.67 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainstartmenuexperiencehost.ydns.eu | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash4284e99939cebf40b8699bed31c82fd6 | — | |
hash961ebce4327b18b39630bfc4edb7ca34 | — | |
hash9799484e3942a6692be69aec1093cb6c | — | |
hash97adb364d695588221d0647676b8e565 | — | |
hashbbb99dfd9bf3a2638e2e9d13693c731c | — | |
hashc98eb5fcddf0763c7676c99c285f6e80 | — | |
hashd80237d48e1bbc2fdda741cbf006851a | — | |
hash21e95fed5fc5c4a10fafbc3882768cce1f6cd7af | — | |
hash38b0e360d58d4ddb17c0a2c4d97909be43a3adc0 | — | |
hash3983a5b4839598ba494995212544da05087b811b | — | |
hash3ab2aa4e9a7a8abcf1ea42b51152f6bb15a1b3c5 | — | |
hash4397920a0b08a31284aff74a0bed9215d5787852 | — | |
hash722a4932576734a08595c7196d87395e6ec653d7 | — | |
hashb3fb8a805d3acc2eda39a83a14e2a73e8b244cf4 | — | |
hash03548c9fad49820c52ff497f90232f68e044958027f330c2c51c80f545944fc1 | — | |
hash08a5d0d8ec398acc707bb26cb3d8ee2187f8c33a3cbdee641262cfc3aed1e91d | — | |
hash3ef2cf8f65a9a6f4955ecd0292af0cd68e65864907d07543c416ab28a2acfa6d | — | |
hash8f3dc1649150961e2bac40d8dabe5be160306bcaaa69ebe040d8d6e634987829 | — | |
hashc208d8d0493c60f14172acb4549dcb394d2b92d30bcae4880e66df3c3a7100e4 | — | |
hashd0fe6555bc72a7a45a836ea137850e6e687998eb1c4465b8ad1fb6119ff882ab | — | |
hashd139bfe642f3080b461677f55768fac1ae1344e529a57732cc740b23e104bff0 | — | |
hashe7666af17732e9a3954f6308bc52866b937ac67099faa212518d5592baca5d44 | — |
Threat ID: 694295c3034dcf495041dbd2
Added to database: 12/17/2025, 11:36:35 AM
Last enriched: 12/17/2025, 11:51:33 AM
Last updated: 2/5/2026, 7:52:20 PM
Views: 162
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown
MediumThey Got In Through SonicWall. Then They Tried to Kill Every Security Tool
MediumDEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
MediumThreatFox IOCs for 2026-02-04
MediumThe Godfather of Ransomware? Inside Cartel Ambitions
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.