Still Circling: Toolkit Keeps Evolving
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.
AI Analysis
Technical Summary
Researchers tracked the Blind Eagle threat actor from May to July 2026, observing multiple exposed staging servers that revealed significant evolution in their toolkit. The toolkit now includes a third string-obfuscation scheme using JavaScript with a custom AES S-box substitution, a RunPE loader leveraging a bare AutoIt3 interpreter staged via GitHub, and a reusable 'Photo Studio' persistence mechanism shared across three toolchains. Additionally, the AsyncRAT variant JC-46 was materially upgraded to incorporate Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC capabilities for banking fraud with browser profile cloning, and a bypass of Chrome App-Bound Encryption v20. The group exhibits selective sophistication despite operational security flaws such as exposed directories and hardcoded credentials, focusing on banking targets in Spanish-speaking countries.
Potential Impact
The threat actor's toolkit enhancements enable more sophisticated malware deployment and persistence, including advanced obfuscation and process injection techniques. The upgraded AsyncRAT JC-46 variant facilitates stealthy remote access, banking fraud via hidden VNC, and credential theft through browser profile cloning and Chrome encryption bypass. These capabilities increase the risk of financial theft and compromise of sensitive banking credentials in targeted regions. Operational security weaknesses may provide defenders with detection opportunities, but the evolving toolkit poses a medium-level threat to banking operations in affected countries.
Mitigation Recommendations
No official patches or fixes are available as this is a malware toolkit used by a threat actor rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed IP addresses (178.16.52.80, 64.89.160.17, 181.235.8.24), domain (rema200426.duckdns.org), and file hashes provided. Implementing detection for the described techniques (e.g., RunPE loaders, process injection, AsyncRAT variants) and restricting AutoIt3 interpreter usage may help mitigate infection. Since the threat actor exhibits operational security weaknesses, leveraging exposed directories and hardcoded credentials for threat hunting could be effective. No vendor advisory or patch information is available; patch status is not applicable.
Affected Countries
Colombia
Indicators of Compromise
- ip: 178.16.52.80
- ip: 64.89.160.17
- hash: a4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff
- hash: a73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4
- ip: 181.235.8.24
- domain: rema200426.duckdns.org
Still Circling: Toolkit Keeps Evolving
Description
Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers tracked the Blind Eagle threat actor from May to July 2026, observing multiple exposed staging servers that revealed significant evolution in their toolkit. The toolkit now includes a third string-obfuscation scheme using JavaScript with a custom AES S-box substitution, a RunPE loader leveraging a bare AutoIt3 interpreter staged via GitHub, and a reusable 'Photo Studio' persistence mechanism shared across three toolchains. Additionally, the AsyncRAT variant JC-46 was materially upgraded to incorporate Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC capabilities for banking fraud with browser profile cloning, and a bypass of Chrome App-Bound Encryption v20. The group exhibits selective sophistication despite operational security flaws such as exposed directories and hardcoded credentials, focusing on banking targets in Spanish-speaking countries.
Potential Impact
The threat actor's toolkit enhancements enable more sophisticated malware deployment and persistence, including advanced obfuscation and process injection techniques. The upgraded AsyncRAT JC-46 variant facilitates stealthy remote access, banking fraud via hidden VNC, and credential theft through browser profile cloning and Chrome encryption bypass. These capabilities increase the risk of financial theft and compromise of sensitive banking credentials in targeted regions. Operational security weaknesses may provide defenders with detection opportunities, but the evolving toolkit poses a medium-level threat to banking operations in affected countries.
Mitigation Recommendations
No official patches or fixes are available as this is a malware toolkit used by a threat actor rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed IP addresses (178.16.52.80, 64.89.160.17, 181.235.8.24), domain (rema200426.duckdns.org), and file hashes provided. Implementing detection for the described techniques (e.g., RunPE loaders, process injection, AsyncRAT variants) and restricting AutoIt3 interpreter usage may help mitigate infection. Since the threat actor exhibits operational security weaknesses, leveraging exposed directories and hardcoded credentials for threat hunting could be effective. No vendor advisory or patch information is available; patch status is not applicable.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-blind-eagles-toolkit-keeps-evolving"]
- Adversary
- APT-C-36
- Pulse Id
- 6a5b639c3194d1cc5f0e281b
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip178.16.52.80 | — | |
ip64.89.160.17 | — | |
ip181.235.8.24 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hasha4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff | — | |
hasha73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainrema200426.duckdns.org | — |
Threat ID: 6a5e02712a4a8d5989efa0a7
Added to database: 07/20/2026, 11:11:45 UTC
Last enriched: 07/20/2026, 11:31:10 UTC
Last updated: 07/20/2026, 21:13:48 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.