Blind Eagle, a new APT group, poses as Colombia's Cyber Police to steal business secrets
Full article594 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The group is carrying out attacks against Colombian government agencies, financial companies and corporations with a presence in Colombia.
Cyberwar is intensifying in South America.
A new hacking group researchers have dubbed Blind Eagle is carrying out targeted attacks against Colombian government agencies, financial companies and corporations with a presence in Colombia.
Blind Eagle has been active since April 2018, posing as Colombian institutions like the National Cyber Police and the Office of the Attorney General to steal intellectual property, according to research published this week by the 360 Enterprise Security Group, which is affiliated with the Chinese security giant Qihoo 360.
Researchers from 360 did not specifically identify the suspects who might be behind the group, which is also referred to as APT-C-36. But they suggested the attacks originated in South America, based on the timing the attacks were sent and the use of the Spanish language in the malware, among other factors.
“[This] APT attack could probably be carried out by neighboring countries,” researchers said. “The background of the victims and duration of the attack indicate the attacker keeps concerned with strategic-level intelligence for a long time.”
Attackers targeted Colombia’s National Institute for the Blind, the Bank of Colombia and a number of energy companies in the country. They also forged information from U.S. companies including Chevron, Energizer, Abbott Laboratories and auto insurance provider Progressive to make themselves seem more legitimate.
The most recent attack outlined in the research occurred on Feb. 14. The phishing email appeared to come from the Colombian National Civil Registry, and was aimed at the National Institute for the Blind.
“After analyzing the mail, we found that the attacker used approaches such as proxy and VPN to hide its PD address when sending emails,” researchers stated. “So the sender’s real IP has not yet been obtained, only to figure out that these messages are sent through [internet database connectors] in Florida.”
Colombia previously was hit with a cyber-espionage campaign known as Machete, first discovered by Kaspersky Lab in 2014. That APT effort targeted numerous countries in South America and worldwide, exfiltrating 100GB of data from 300 victims, according to Cylance. The campaign still was active in 2017.
The report comes after Motherboard detailed how hackers allegedly affiliated with the Venezuelan government tried luring activists into compromising email and social media credentials.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apt-c-36-blind-eagle-colombia/