CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

BlindEagle Targets Colombian Government Agency with Caminho and DCRAT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6271

As cited

Copy frozen at (site build).

threat intel

BlindEagle Targets Colombian Government Agency with Caminho and DCRAT

In early September 2025, Zscaler ThreatLabz identified a spear phishing campaign by BlindEagle targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attack chain used a fraudulent judicial-themed email sent from a compromised internal account, leading to a clickable SVG attachment that deployed nested JavaScript and PowerShell scripts to download Caminho malware, which in turn delivered DCRAT remote access trojan. The campaign employed steganography, Discord for payload hosting, process hollowing with MSBuild.exe, and AES-256 encrypted DCRAT configurations with certificate-based command and control authentication.

Why it matters: Colombian government agencies and organizations in Spanish-speaking regions must audit email security controls, employee account access, and sandbox detection mechanisms, as BlindEagle demonstrates increasingly sophisticated multi-stage attacks exploiting internal trust and legitimate services; security teams should monitor for Caminho, DCRAT, and the C2 domain startmenuexperiencehost.ydns.eu, and implement endpoint detection and response (EDR) solutions capable of detecting process hollowing and AMSI bypass techniques.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

BlindEagle Targets Colombian Government Agency with Caminho and DCRAT

In early September 2025, Zscaler ThreatLabz identified a spear phishing campaign by BlindEagle targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism. The attack chain used a fraudulent judicial-themed email sent from a compromised internal account, leading to a clickable SVG attachment that deployed nested JavaScript and PowerShell scripts to download Caminho malware, which in turn delivered DCRAT remote access trojan. The campaign employed steganography, Discord for payload hosting, process hollowing with MSBuild.exe, and AES-256 encrypted DCRAT configurations with certificate-based command and control authentication.

Why it matters: Colombian government agencies and organizations in Spanish-speaking regions must audit email security controls, employee account access, and sandbox detection mechanisms, as BlindEagle demonstrates increasingly sophisticated multi-stage attacks exploiting internal trust and legitimate services; security teams should monitor for Caminho, DCRAT, and the C2 domain startmenuexperiencehost.ydns.eu, and implement endpoint detection and response (EDR) solutions capable of detecting process hollowing and AMSI bypass techniques.

VendorsMicrosoftAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary