Blind Eagle malware operators' tools leaked
A criminal running phishing scams linked to the Blind Eagle hacking group got infected by the same kind of password-stealing malware they use on victims. That accident let researchers see inside their operation, including malware builders, fake government websites, and mailing tools used to trick people in Colombia.
- Report priority
- Medium
- Targets
- Windows
How it works
Researchers traced a GitHub account used to host malware loader files back to an email address, then found that same address inside a stolen-credential database, which pointed to an infected device that had been used to build and stage the phishing campaign.
What to do
Colombian residents should be cautious of unexpected emails claiming to be from the Consejo Superior de la Judicatura or Bogota's Secretaria Distrital de Movilidad that push a password-protected archive to open on a PC.
Treat unsolicited notices from Colombian judicial or traffic agencies with suspicion, the normal update channel, and avoid opening password-protected archives from unexpected emails.
Technical details
Affected software: Windows
An operator builds phishing pages that pretend to be notices from Colombia's judicial council and Bogota's traffic authority. The pages push victims to download password-protected archives and open them on a Windows PC or laptop. While preparing this campaign, the operator's own machine got infected by information-stealing malware, and the stolen data from that device later leaked into a public stealer-log collection that researchers could search.
The exposed workstation held build folders for AsyncRAT, DcRat, Remcos, Quasar RAT, and XWorm, plus a folder of prior Remcos configs named after other victim systems, suggesting reuse across earlier campaigns. It also contained SendBlaster bulk-mail configs pointed at an external SMTP relay, browser history touching Brevo, Mailrelay, HubSpot, DreamHost, HostGator, and Firebase, and evidence of research into FUD Crypter, MI6 Crypter, and PolyCrypt, tools used to make malware harder for antivirus to detect. Attribution to a specific person remains unconfirmed; the findings describe a device apparently used for malicious activity.