Back to Blog
Threat Analysis10 min read

Blind Eagle: How a Persistent Hacker Group Targets South America's Financial Sector

The Blind Eagle hacker group has become one of the most persistent cyber threats in South America, relentlessly targeting banks and financial institutions — particularly in Colombia. This analysis breaks down their tactics, infrastructure, and persistence mechanisms.

AN
Antonioni Nascimento OliveiraKRX Labs Security Research
01

Who Is Blind Eagle

The Actors

Blind Eagle (also known as Águila Ciega) is a South American cyber-espionage group, financially motivated with a focus on stealing sensitive information and credentials.

Primary Targets

Banks (Bancolombia, BBVA), government agencies, and high-value individuals within Colombia and neighboring countries.

02

The Attack Chain: Old Tricks, Modern Tools

Blind Eagle employs a combination of tried-and-true social engineering with updated malware delivery techniques.

1. The Lure — Phishing

They craft fake banking websites, visually indistinguishable from legitimate sites. Victims are directed through phishing emails designed to create urgency.

2. The Trap — VBS Files

Victims download a Visual Basic Script (VBS) — an old but still functional Windows scripting technology. It runs silently, often bypasses basic antivirus, and is simple and lightweight.

3. The Payload — Remote Access Trojans

The VBS fetches and installs the real payload — AsyncRAT and Remcos RAT. These give attackers full control: keystroke logging, file exfiltration, webcam/microphone activation, and network pivoting.

03

Bulletproof Hosting: Staying "Invisible"

A key discovery by researchers was how Blind Eagle keeps their malicious infrastructure online despite constant takedown efforts.

Proton66

Blind Eagle hosts phishing sites and command-and-control servers on a Russian bulletproof hosting service called Proton66 — designed specifically for cybercriminals, it ignores abuse complaints and takedown requests.

04

Defense Strategies

For Individuals

Do not click links in unsolicited emails claiming to be from banks.

Verify the URL before entering credentials — check for HTTPS and correct domain names.

Keep Windows updated and disable unnecessary scripting engines.

Run reputable endpoint protection capable of detecting RATs.

For Organizations

Conduct phishing awareness training regularly.

Implement advanced email filtering to block malicious attachments and links.

Monitor outbound traffic for connections to known C2 servers.

Isolate infected systems immediately to contain RAT infections.

05

Conclusion

Blind Eagle exemplifies a persistent, adaptable threat actor combining social engineering, legacy technologies, modern malware, and bulletproof infrastructure to compromise victims in the South American financial sector.

Key takeaway: Understanding their tactics and proactively defending against them reduces risk significantly. Train employees, filter emails, monitor networks, and isolate infections immediately.

Frequently Asked Questions

Who is Blind Eagle?

Blind Eagle is a South American cyber-espionage group that targets banks and government entities, primarily in Colombia, using phishing and RATs to steal sensitive data.

What is a VBS file and why is it dangerous?

A VBS (Visual Basic Script) file is a Windows scripting file. Attackers use it to silently execute malicious commands and download malware.

What are AsyncRAT and Remcos RAT?

They are Remote Access Trojans — malware that provides attackers with full remote control over infected systems.

What is bulletproof hosting?

Bulletproof hosting is a service that ignores abuse reports and takedown requests, enabling cybercriminals to host malicious content and stay online.

© 2026 KRX Labs