Executive Summary
The threat actor known as Blind Eagle (also tracked as APT-C-36) continues to target Latin American organizations with increasingly sophisticated malware delivery toolchains. Recent analysis reveals the group is iterating on its obfuscation methods, employing custom AES S-boxes and a new project codenamed JC-46. This upgraded toolkit leverages a highly customized version of AsyncRAT designed specifically for banking fraud through advanced browser manipulation.
Technically, the group has shifted from simple process hollowing to abusing the Windows Notification Facility (WNF) for stealthy process injection, effectively bypassing traditional EDR behavioral heuristics. The JC-46 build also includes a functional bypass for Google Chrome's App-Bound Encryption (ABE) v20, allowing the actor to steal session cookies and credentials despite modern browser protections. This transition toward more resilient evasion techniques demonstrates a dedicated investment in maintaining access to high-value financial targets.
Blind Eagle's operational tempo remains high, characterized by the use of Russian bulletproof hosting (Proton66), open-directory staging servers, and persistent infrastructure reuse. Despite these advancements, the group relies on a consistent delivery skeleton involving VBScript-to-PowerShell chains and recurring persistence artifacts, such as the 'Photo Studio' scheduled task, which provides defenders with durable hunting opportunities.
