Full Report
2025-03-11 • The Hacker News • Ravie Lakshmanan • win.asyncrat, win.njrat, win.quasar_rat, win.remcos Open article on Malpedia
Analysis Summary
# Threat Actor: Blind Eagle
## Attribution & Identity
The threat actor is identified as **Blind Eagle**. No specific nation-state attribution is explicitly mentioned in the provided context snippet, but their targeting focuses on Colombian institutions.
## Activity Summary
Blind Eagle has been observed actively hacking Colombian institutions using a combination of known vulnerabilities, specific Remote Access Trojans (RATs), and attacks leveraging GitHub platforms.
## Tactics, Techniques & Procedures
- Exploitation of **NTLM flaws** for initial access or lateral movement.
- Utilization of various **Remote Access Trojans (RATs)**.
- Use of **GitHub-based attacks** (likely for staging malware or C2 communication).
- Specific malware families mentioned include: `win.asyncrat`, `win.njrat`, `win.quasar_rat`, and `win.remcos`.
## Targeting
- Sectors: Institutions (General, focusing on Colombian entities).
- Geography: **Colombia**.
- Victims: Colombian institutions.
## Tools & Infrastructure
- Malware families used:
- AsyncRAT (`win.asyncrat`)
- NJRAT (`win.njrat`)
- Quasar RAT (`win.quasar_rat`)
- Remcos (`win.remcos`)
- Infrastructure: Attacks leverage **GitHub-based techniques**.
## Implications
Blind Eagle poses a persistent threat to Colombian infrastructure, employing a mix of commodity RATs alongside known exploitation techniques (NTLM flaws) to achieve stealthy and persistent compromise. The reliance on readily available tools suggests a focus on efficiency and broad targeting within their area of interest.
## Mitigations
- Patching and mitigating known NTLM vulnerabilities.
- Implementing robust Endpoint Detection and Response (EDR) capable of detecting and blocking common RAT signatures and execution patterns associated with AsyncRAT, NJRAT, Quasar RAT, and Remcos.
- Auditing organizational reliance on GitHub for non-standard code/payload delivery, treating such activity as high-risk.