Security researchers have published evidence of a hacking group, known as Blind Eagle, which is targeting entities and individuals in Colombia, Ecuador, Chile, Panama, and other Latin American nations with RAT malware.

Among the targets are government institutions, financial companies, and energy, oil, and gas companies.
" Blind Eagle has demonstrated adaptability in shaping the targets of its cyberattacks and flexibility to switch between attacks with purely financial motives and espionage attacks ," Kaspersky said in a report.
See also: Mad Liberator: New group targets AnyDesk users and steals data
Blind Eagle is believed to have been active since at least 2018. The Spanish-speaking group is known for using spear-phishing techniques to distribute various trojans (RATs), including AsyncRAT, BitRAT, Lime RAT, NjRAT, Quasar RAT, and Remcos RAT. In March, eSentire detailed the use of a malware loader called Ande Loader to spread Remcos RAT and NjRAT.
The attack begins with a phishing email impersonating legitimate government entities and financial and banking services. The email warns recipients to take urgent actionby clicking on a link that supposedly takes them to the official website of the impersonated entity.
The messages also include a PDF or Microsoft Word attachment containing the same URL. There may also be some additional details that try to lend a sense of legitimacy and make the situation seem more urgent.
The first set of URLs directs users to websites controlled by the attackers. These websites host an initial dropper, but only after it is determined that the victim is from a country on Blind Eagle's target list. Otherwise, victims are directed to the real website of the organization being impersonated by the attackers.
The initial dropper comes in the file ZIP, which, in turn, embeds a Visual Basic Script (VBS), responsible for retrieving the next-stage payload from a remote server. These servers can range from image hosting sites to legitimate services like Discord and GitHub.
See also: Hunters International targets IT employees with SharpRhino RAT
The second-stage malware, often disguised as a DLL or .NET injector , then contacts another malicious server to retrieve the final-stage trojan.
“The group often uses process injection to execute the RAT in the memory of a legitimate process, thereby evading defenses,” Kaspersky said. However, according to researchers, the group’s preferred technique is process hollowing.

Blind Eagle uses RATs for cyber espionage and theft of financial and other sensitive information.
“As simple as Blind Eagle’s techniques and processes may seem, their effectiveness allows the group to maintain a high level of activity,” Kaspersky concluded. “By continuously executing cyberespionage and theft , Blind Eagle remains a significant threat in the region.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What are the best methods for protecting against RAT malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
Installing reliable security is another essential method of malware protection. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing protection.
See also: Gh0st RAT Trojan: Targets Chinese Windows Users via Fake Chrome Site
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware.
Source: thehackernews.com
