Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Five clusters of Blind Eagle target Columbia using rats, fish ladies and dynamic DNS infrastructure
Celebrities

Five clusters of Blind Eagle target Columbia using rats, fish ladies and dynamic DNS infrastructure

By August 27, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Cybersecurity researchers discovered five different activity clusters linked to a permanent threat actor known as Blind Eagle between May 2024 and July 2025.

These attacks observed by future recorded Insikt groups targeted a variety of casualties, but were primarily targeted within the Colombian government at the local, city and federal levels. The Threat Intelligence Company tracks activities under the name Tag-144.

“Clusters share similar tactics, techniques and procedures (TTPs), including open source and crack remote access trojans (rats), dynamic domain providers, and staging legitimate Internet services (LI), but differ significantly in infrastructure, malware deployment, and other ways of operation.

Blind Eagle has a history of targeting South American organizations since at least 2018, with the attacks reflecting both cyber-espionage and economically driven motivations. This has been proven in recent campaigns that include bank-related keylogs and browser monitoring, as well as targeting government agencies using various remote access trojans (RATs).

Cybersecurity

The group’s targets of attack include judicial and tax authorities, including entities in the financial, oil, energy, education, healthcare, manufacturing and professional services sectors. The business spans Spanish-speaking users from Colombia, Ecuador, Chile, Panama and, in some cases, North American.

Attack chains are now usually impersonating local government agencies, tempting recipients to open malicious documents, or clicking hidden links using URL shorteners like Cort.[.]As,Acortaurl[.]com, and gtly[.]To.

Blind Eagle leverages geofencing tricks to redirect users to official government websites when trying to send messages using a compromised email account and navigate to attacker-controlled infrastructure outside of Colombia or Ecuador.

“The TAG-144’s Command and Control (C2) infrastructure often includes the IP address of your Columbia ISP along with virtual private servers (VPSs) such as Proton666 and VPN services such as Powerhouse Management, FrootVPN, and Torguard. This setup is further enhanced by the use of dynamic DNS services, including duckdns.[.]org, ip-ddns[.]com, and noip[.]com. “

Threat groups also use legitimate internet services to set up payloads for malicious content and Evard detection, such as Bitbucket, Discord, Dropbox, Github, Google Drive, The Internet Archive, lovestoblog.com, Paste.ee, Tagbox, and the lesser known Brazilian image hosting website.

A recent campaign, organized by Threat Actor, employs visual basic script files as droppers to run dynamically generated PowerShell scripts at runtime. This will access an external server that downloads the injector modules responsible for loading Limerat, DCRAT, Asynchronous, or REMCOS RAT.

Regional focus aside, hacking groups have consistently relied on the same techniques since their emergence, highlighting that “established methods” continue to provide high success rates in the region.

A recorded Future analysis of Blind Eagle’s campaign discovered five activities –

Cluster 1 (February to July 2025). It targets Colombian government agencies that only cover DCRAT, Asyncrat, and Remcos Rat Cluster 2. Remcos Rat Cluster 4 (May 2024 to February 2025). This is related to malware and phishing infrastructure caused by TAG-144, and the phishing page mimics Banco Davivivienda, Bancolombia and BBVA Cluster 5 (March to July).

The digital miscives used in these campaigns come with an SVG attachment, so we will contact the discord CDN of the CDN to get the JavaScript payload that retrieves the PowerShell script from Paste.ee. The PowerShell script is designed to decode and run another PowerShell payload that retrieves JPG images hosted in an Internet archive and extracts embedded .NET assemblies from it.

Identity Security Risk Assessment

Interestingly, the cracked version of Asyncrat used in the attack has been previously observed in connection with invasion activity mounted by threat activists Red Akodon and Shadow Vector, both of which have targeted Colombia for the past year.

Nearly 60% of blinded Eagle activities observed during the analysis targeted the government sector, followed by education, healthcare, retail, transportation, defense and oil verticals.

“TAG-144 targets other sectors and may be linked to invasions of additional South American countries such as Ecuador and the invasion of Spanish-speaking victims in the US, but its main focus has consistently remained Colombia, particularly government entities,” says Future, recorded.

“This persistent targeting raises questions about the true motivations of threat groups, such as whether it will only serve as a financially driven threat actor that leverages established tools, techniques, and monetization strategies.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe US expands Haleu fuel commitment to boost nuclear power
Next Article SalesLoftOAUTH violation via Drift AI chat agent publishes Salesforce customer data

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.