Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Still Circling: Toolkit Keeps Evolving

0
Medium
Published: 07/18/2026 (07/18/2026, 11:29:32 UTC)
Source: AlienVault OTX General

Description

Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 11:31:10 UTC

Technical Analysis

Researchers tracked the Blind Eagle threat actor from May to July 2026, observing multiple exposed staging servers that revealed significant evolution in their toolkit. The toolkit now includes a third string-obfuscation scheme using JavaScript with a custom AES S-box substitution, a RunPE loader leveraging a bare AutoIt3 interpreter staged via GitHub, and a reusable 'Photo Studio' persistence mechanism shared across three toolchains. Additionally, the AsyncRAT variant JC-46 was materially upgraded to incorporate Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC capabilities for banking fraud with browser profile cloning, and a bypass of Chrome App-Bound Encryption v20. The group exhibits selective sophistication despite operational security flaws such as exposed directories and hardcoded credentials, focusing on banking targets in Spanish-speaking countries.

Potential Impact

The threat actor's toolkit enhancements enable more sophisticated malware deployment and persistence, including advanced obfuscation and process injection techniques. The upgraded AsyncRAT JC-46 variant facilitates stealthy remote access, banking fraud via hidden VNC, and credential theft through browser profile cloning and Chrome encryption bypass. These capabilities increase the risk of financial theft and compromise of sensitive banking credentials in targeted regions. Operational security weaknesses may provide defenders with detection opportunities, but the evolving toolkit poses a medium-level threat to banking operations in affected countries.

Mitigation Recommendations

No official patches or fixes are available as this is a malware toolkit used by a threat actor rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed IP addresses (178.16.52.80, 64.89.160.17, 181.235.8.24), domain (rema200426.duckdns.org), and file hashes provided. Implementing detection for the described techniques (e.g., RunPE loaders, process injection, AsyncRAT variants) and restricting AutoIt3 interpreter usage may help mitigate infection. Since the threat actor exhibits operational security weaknesses, leveraging exposed directories and hardcoded credentials for threat hunting could be effective. No vendor advisory or patch information is available; patch status is not applicable.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-blind-eagles-toolkit-keeps-evolving"]
Adversary
APT-C-36
Pulse Id
6a5b639c3194d1cc5f0e281b
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip178.16.52.80
ip64.89.160.17
ip181.235.8.24

Hash

ValueDescriptionCopy
hasha4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff
hasha73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4

Domain

ValueDescriptionCopy
domainrema200426.duckdns.org

Threat ID: 6a5e02712a4a8d5989efa0a7

Added to database: 07/20/2026, 11:11:45 UTC

Last enriched: 07/20/2026, 11:31:10 UTC

Last updated: 07/20/2026, 21:13:48 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses