HomeSecurityBlind Eagle: Targets Colombia's insurance sector with Quasar RAT

Blind Eagle: Targets Colombia's insurance sector with Quasar RAT

Colombia's insurance sector is being targeted by a malicious gang called Blind Eagle.

Blind Eagle Quasar RAT insurance sector

This threat aims to deliver a customized version of a well-known trojan , the Quasar RAT, by June 2024.

“The attacks originate from phishing emails impersonating the Colombian tax authority,” said Gaetano Pellegrino, a researcher at Zscaler ThreatLabz, in a recent analysis published last week.

See also: Phishing attacks on gov.gr and Greek Banks

The advanced threat (APT), also known as AguilaCiega, APT-C-36, and APT-Q-98, has a proven track record of targeting organizations and individuals in South America, with a particular focus on the government and financial sectors in Colombia and Ecuador.

Attack chains, as Kaspersky, arise from phishing emails that urge recipients to click on malicious links. These links act as the starting point for the infection process.

The links, either included in a PDF attachment or mentioned directly in the body of the email, lead to ZIP files hosted in a Google Drive folder associated with a compromised account of a regional government agency in Colombia.

“The hacking group used the lure of sending a notice to the victim, claiming it was a seizure order for unpaid taxes,” Pellegrino observed. “This was intended to create a sense of urgency and push the victim to take immediate action.”

Read more:

The malicious file contains a variant of the Quasar RAT called BlotchyQuasar, which is packaged in multiple layers of obfuscation, using tools such as DeepSea and ConfuserEx, to thwart analysis and reverse engineering attempts. This variant was previously analyzed by IBM X-Force in July 2023.

The malware has functionalities such as keystroke logging, executing shell commands, stealing data from web browsers and FTP clients, as well as monitoring the victim's interactions with specific banking and payment services in Colombia and Ecuador.

Blind Eagle Quasar RAT Colombia

It also leverages Pastebin as a tool for dead-drop resolution, facilitating command and control (C2) domain. The threat actor uses Dynamic DNS (DDNS) services to host the C2 domain.

See also: Blind Eagle hackers target Latin America with RAT malware

“Blind Eagle typically protects its infrastructure using a combination of VPN nodes and compromised routers, primarily in Colombia,” Pellegrino said. “This attack highlights the ongoing implementation of this strategy.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS