SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIn mid-2025, Colombian users became the target of a coordinated campaign known as Shadow Vector, which combined local social engineering with privilege escalation exploits and court-themed SVG lure documents. Multiple vendors reported on the operation, attributing it to activity consistent with the "Blind Eagle" (APT C 36) threat group. While technically straightforward, the campaign shows how regional actors can merge simple malware with culturally resonant lures and creative delivery methods to achieve their goals.
Active since at least 2018, Blind Eagle has run relentless phishing campaigns across Latin America, often impersonating government agencies, banks, and energy firms. Their playbook relies on commodity RATs, public hosting services, and fast adoption of new delivery tricks. Even without advanced tools, they succeed by exploiting trust, abusing infrastructure, and adapting quickly to local contexts, showing why low-cost actors remain a persistent threat.


Santiago Pontiroli is a cybersecurity expert focusing on threat intelligence efforts at Acronis as Lead Scurity Researcher of the Acronis Threat Research Unit (TRU).
Read more about Santiago Pontiroli













