Blind Eagle Evolves with JC-46 AsyncRAT Build
Score: 8/10

Blind Eagle Evolves with JC-46 AsyncRAT Build

Blind Eagle (APT-C-36) is utilizing a modernized JC-46 AsyncRAT build featuring WNF process injection and a Chrome App-Bound Encryption bypass to target Latin American financial interests.

Executive Summary

The threat actor known as Blind Eagle (also tracked as APT-C-36) continues to target Latin American organizations with increasingly sophisticated malware delivery toolchains. Recent analysis reveals the group is iterating on its obfuscation methods, employing custom AES S-boxes and a new project codenamed JC-46. This upgraded toolkit leverages a highly customized version of AsyncRAT designed specifically for banking fraud through advanced browser manipulation.

Technically, the group has shifted from simple process hollowing to abusing the Windows Notification Facility (WNF) for stealthy process injection, effectively bypassing traditional EDR behavioral heuristics. The JC-46 build also includes a functional bypass for Google Chrome's App-Bound Encryption (ABE) v20, allowing the actor to steal session cookies and credentials despite modern browser protections. This transition toward more resilient evasion techniques demonstrates a dedicated investment in maintaining access to high-value financial targets.

Blind Eagle's operational tempo remains high, characterized by the use of Russian bulletproof hosting (Proton66), open-directory staging servers, and persistent infrastructure reuse. Despite these advancements, the group relies on a consistent delivery skeleton involving VBScript-to-PowerShell chains and recurring persistence artifacts, such as the 'Photo Studio' scheduled task, which provides defenders with durable hunting opportunities.

Key Details

Threat Name

Blind Eagle

Affects

—

Adversary

Blind Eagle

Malware/Tools

AsyncRAT, Paralell.dll, XLoader, NjRAT, LimeRAT

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure10
Technical Depth9

Sources