As cited
Copy frozen at (site build).
threat intel
BlindEagle Targets Colombian Government Agency with Caminho and DCRAT
In early September 2025, Zscaler ThreatLabz identified a spear phishing campaign by BlindEagle targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attack chain used a fraudulent judicial-themed email sent from a compromised internal account, leading to a clickable SVG attachment that deployed nested JavaScript and PowerShell scripts to download Caminho malware, which in turn delivered DCRAT remote access trojan. The campaign employed steganography, Discord for payload hosting, process hollowing with MSBuild.exe, and AES-256 encrypted DCRAT configurations with certificate-based command and control authentication.
Why it matters: Colombian government agencies and organizations in Spanish-speaking regions must audit email security controls, employee account access, and sandbox detection mechanisms, as BlindEagle demonstrates increasingly sophisticated multi-stage attacks exploiting internal trust and legitimate services; security teams should monitor for Caminho, DCRAT, and the C2 domain startmenuexperiencehost.ydns.eu, and implement endpoint detection and response (EDR) solutions capable of detecting process hollowing and AMSI bypass techniques.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
BlindEagle Targets Colombian Government Agency with Caminho and DCRAT
In early September 2025, Zscaler ThreatLabz identified a spear phishing campaign by BlindEagle targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attack chain used a fraudulent judicial-themed email sent from a compromised internal account, leading to a clickable SVG attachment that deployed nested JavaScript and PowerShell scripts to download Caminho malware, which in turn delivered DCRAT remote access trojan. The campaign employed steganography, Discord for payload hosting, process hollowing with MSBuild.exe, and AES-256 encrypted DCRAT configurations with certificate-based command and control authentication.
Why it matters: Colombian government agencies and organizations in Spanish-speaking regions must audit email security controls, employee account access, and sandbox detection mechanisms, as BlindEagle demonstrates increasingly sophisticated multi-stage attacks exploiting internal trust and legitimate services; security teams should monitor for Caminho, DCRAT, and the C2 domain startmenuexperiencehost.ydns.eu, and implement endpoint detection and response (EDR) solutions capable of detecting process hollowing and AMSI bypass techniques.
- Source published
- First seen by Cybersecurity Tracker