Contact Sales
Contact Sales

Whenever, Wherever… Blind Eagle Attacks: The Shadow Vector Case

Whenever, Wherever… Blind Eagle Attacks: The Shadow Vector Case (PDF, 1.00MB)Last updated: 26 Jan, 2026
Presented by:
Santiago Pontiroli
Santiago Pontiroli

In mid-2025, Colombian users became the target of a coordinated campaign known as Shadow Vector, which combined local social engineering with privilege escalation exploits and court-themed SVG lure documents. Multiple vendors reported on the operation, attributing it to activity consistent with the "Blind Eagle" (APT C 36) threat group. While technically straightforward, the campaign shows how regional actors can merge simple malware with culturally resonant lures and creative delivery methods to achieve their goals.

Active since at least 2018, Blind Eagle has run relentless phishing campaigns across Latin America, often impersonating government agencies, banks, and energy firms. Their playbook relies on commodity RATs, public hosting services, and fast adoption of new delivery tricks. Even without advanced tools, they succeed by exploiting trust, abusing infrastructure, and adapting quickly to local contexts, showing why low-cost actors remain a persistent threat.

SANS Cyber Threat Intelligence Summit 2026