← Back to Feed

Still Circling: Blind Eagle's Toolkit Keeps Evolving

July 17, 2026 · LevelBlue SpiderLabs · Severity: HIGH

This article updates on the Blind Eagle threat actor's ongoing activities. The group has maintained its use of Russian bulletproof hosting and continues to evolve its toolkit. LevelBlue SpiderLabs reports that the actor shows no signs of slowing down.

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.

Key Takeaways

  • Blind Eagle threat actor continues to evolve its toolkit for Latin American targets.
  • The group uses Russian bulletproof hosting provider Proton66 for delivery infrastructure.
  • Despite previous reports, Blind Eagle remains active and constantly developing new capabilities.
☕ Buy a Coffee