Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

US agencies warn of an increase in Iran’s cyberattacks on defense, OT networks and critical infrastructure

Europol will dismantle a $540 million cryptocurrency fraud network and arrest five suspects

Tiny AI ERP startup Campfire has acquired a huge number of startups from NetSuite.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Blind Eagle uses Proton 66 hosting for fishing and rat deployment at the Bank of Columbia
Identity

Blind Eagle uses Proton 66 hosting for fishing and rat deployment at the Bank of Columbia

userBy userJune 30, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 30, 2025Ravi LakshmananCybercrime/Vulnerability

Hosting for Proton66 Fishing, Rat

The threat actor known as Blind Eagle is attributed to a high degree of confidence in the use of Russian bulletproof hosting service Proton66.

TrustWave SpiderLabs said in a report published last week that this connection can be created by pivoting from Proton66-related digital assets, leading to the discovery of an active threat cluster that leverages visual basic script (VBS) files as the first attack vector and installs shelf remote access trojan (RAT).

Many threat actors rely on bulletproof hosting providers like Proton66, as these services intentionally ignore abuse reports and legal takedown requests. This allows attackers to easily run phishing sites, command and control servers, and malware delivery systems without interruption.

Cybersecurity companies said they have identified a set of domains with similar naming patterns (e.g. gfast.duckdns[.]org, njfast.duckdns[.]org) Starting in August 2024, they all resolved to the same IP address (“45.135.232[.]38”) It is associated with proton 66.

Using dynamic DNS services such as DuckDNS also plays an important role in these operations. Instead of registering a new domain each time, an attacker rotates subdomains tied to a single IP address, making detection more difficult for defenders.

Cybersecurity

“The domain in question was used to host a variety of malicious content, including phishing pages and VBS scripts, which act as an early stage in malware deployment,” said security researcher Serhii Melnyk. “These scripts act as loaders for second-stage tools, which are publicly available in this campaign and are often limited to open source rats.”

Visual Basic Script (VBS) may seem outdated, but it is a go-to tool for early access due to its compatibility with Windows systems and the ability to run quietly in the background. The attacker uses it to download a malware loader, bypass the antivirus tool, and blend it into normal user activity. These lightweight scripts are often the first step in a multi-stage attack, later deploying remote access trojans (rats), data steelers, or keyloggers.

The phishing page has been discovered by legitimate Colombian banks and financial institutions, including Bancolombia, BBVA, Bangkokaha Social, and Dabi Vienda. Blind Eagle, also known as Aguilaciega, Apt-C-36, and APT-Q-98, is known for its targets for entities in South America, particularly Colombia and Ecuadorian.

Deceptive sites are designed to harvest user credentials and other sensitive information. Hosted on your infrastructure, VBS payloads are equipped with the ability to retrieve encrypted executables from remote servers, essentially serving as a loader for commodity rats such as Asyncrat and Remcos rats.

Furthermore, analysis of the VBS code revealed overlap with VBS-crypter. It is a tool linked to subscription-based crypto services called Cryptors and Tools, which are used to bloat and pack VBS payloads to avoid detection.

TrustWave said it has discovered a botnet panel that allows users to “control infected machines, retrieve detached data and interact with infected endpoints through the wide set of features normally found in the Commodity Rat Management Suite.

Cybersecurity

This disclosure comes when Darktrace has been targeting Colombian organizations since November 2024 and reveals details of the blind Eagle campaign targeting Colombian organizations by taking advantage of the currently patched Windows flaw (CVE-2024-43451) to download and run the next stage payload.

“The persistence of blind Eagle and the ability to adapt tactics even after patches are released, and the speed at which the group was able to continue using pre-established TTPS highlights, are not essential for timely vulnerability management and patch applications, but not standalone defense,” the company said.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAI Energy Council discusses how power grids unlock AI benefits
Next Article The cursor launches a web app to manage the AI ​​coding agent
user
  • Website

Related Posts

US agencies warn of an increase in Iran’s cyberattacks on defense, OT networks and critical infrastructure

June 30, 2025

Europol will dismantle a $540 million cryptocurrency fraud network and arrest five suspects

June 30, 2025

A practical approach to NHI inventory

June 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

US agencies warn of an increase in Iran’s cyberattacks on defense, OT networks and critical infrastructure

Europol will dismantle a $540 million cryptocurrency fraud network and arrest five suspects

Tiny AI ERP startup Campfire has acquired a huge number of startups from NetSuite.

The cursor launches a web app to manage the AI ​​coding agent

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

The Digital Twin Revolution: Reshaping Industry 4.0

1-inch rollout expanded bug bounty features rewards up to $500,000

PhysicsX raises $135 million to bring AI-first engineering to aerospace, automobiles and energy

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.