Still Circling: Toolkit Keeps Evolving
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.
AI Analysis
Technical Summary
Researchers tracked the Blind Eagle threat actor from May to July 2026 through exposed staging servers, revealing significant toolkit enhancements. The toolkit now includes a third string-obfuscation scheme using JavaScript with a custom AES S-box substitution, a RunPE loader using a bare AutoIt3 interpreter staged via GitHub, and a reusable 'Photo Studio' persistence mechanism shared across three toolchains. The AsyncRAT variant JC-46 was materially upgraded to incorporate Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC capabilities for banking fraud with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security flaws like exposed directories and hardcoded credentials, the actor demonstrates selective sophistication targeting banking operations in Spanish-speaking countries, particularly Colombia.
Potential Impact
The enhancements in the Blind Eagle toolkit enable more sophisticated malware deployment and persistence, including advanced obfuscation and process injection techniques. The upgraded AsyncRAT JC-46 variant facilitates stealthy remote access, banking fraud via hidden VNC, and credential theft through browser profile cloning and bypassing Chrome encryption. These capabilities increase the risk of financial theft and compromise of sensitive banking credentials in targeted regions. Operational security weaknesses may provide defenders with detection opportunities. Overall, the evolving toolkit poses a medium-level threat to banking operations in affected countries.
Mitigation Recommendations
No official patches or fixes are available as this is a malware toolkit used by a threat actor rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed IP addresses (178.16.52.80, 64.89.160.17, 181.235.8.24), domain (rema200426.duckdns.org), and file hashes provided. Detection efforts should focus on the described techniques including RunPE loaders, process injection, AsyncRAT variants, and restricting AutoIt3 interpreter usage. Leveraging the threat actor's operational security weaknesses, such as exposed directories and hardcoded credentials, for threat hunting may be effective. Patch status is not applicable.
Affected Countries
Colombia
Indicators of Compromise
- ip: 178.16.52.80
- ip: 64.89.160.17
- hash: a4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff
- hash: a73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4
- ip: 181.235.8.24
- domain: rema200426.duckdns.org
Still Circling: Toolkit Keeps Evolving
Description
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers tracked the Blind Eagle threat actor from May to July 2026 through exposed staging servers, revealing significant toolkit enhancements. The toolkit now includes a third string-obfuscation scheme using JavaScript with a custom AES S-box substitution, a RunPE loader using a bare AutoIt3 interpreter staged via GitHub, and a reusable 'Photo Studio' persistence mechanism shared across three toolchains. The AsyncRAT variant JC-46 was materially upgraded to incorporate Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC capabilities for banking fraud with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security flaws like exposed directories and hardcoded credentials, the actor demonstrates selective sophistication targeting banking operations in Spanish-speaking countries, particularly Colombia.
Potential Impact
The enhancements in the Blind Eagle toolkit enable more sophisticated malware deployment and persistence, including advanced obfuscation and process injection techniques. The upgraded AsyncRAT JC-46 variant facilitates stealthy remote access, banking fraud via hidden VNC, and credential theft through browser profile cloning and bypassing Chrome encryption. These capabilities increase the risk of financial theft and compromise of sensitive banking credentials in targeted regions. Operational security weaknesses may provide defenders with detection opportunities. Overall, the evolving toolkit poses a medium-level threat to banking operations in affected countries.
Defensive Guidance
No official patches or fixes are available as this is a malware toolkit used by a threat actor rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed IP addresses (178.16.52.80, 64.89.160.17, 181.235.8.24), domain (rema200426.duckdns.org), and file hashes provided. Detection efforts should focus on the described techniques including RunPE loaders, process injection, AsyncRAT variants, and restricting AutoIt3 interpreter usage. Leveraging the threat actor's operational security weaknesses, such as exposed directories and hardcoded credentials, for threat hunting may be effective. Patch status is not applicable.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-blind-eagles-toolkit-keeps-evolving"]
- Adversary
- APT-C-36
- Pulse Id
- 6a5b639c3194d1cc5f0e281b
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip178.16.52.80 | — | |
ip64.89.160.17 | — | |
ip181.235.8.24 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hasha4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff | — | |
hasha73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainrema200426.duckdns.org | — |
Threat ID: 6a5e02712a4a8d5989efa0a7
Added to database: 07/20/2026, 11:11:45 UTC
Last enriched: 08/17/2026, 12:42:08 UTC
Last updated: 09/01/2026, 10:25:12 UTC
Views: 161
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.