Still Circling: Blind Eagle's Toolkit Keeps Evolving
July 17, 2026 · LevelBlue SpiderLabs · Severity: HIGH
Blind Eagle (APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor targeting Latin America, continues to evolve its toolkit and infrastructure. In June 2025, LevelBlue SpiderLabs linked the group to Russian bulletproof hosting provider Proton66, where it migrated part of its VBScript delivery infrastructure. A year later, the group remains active, refining its operations and expanding its capabilities, demonstrating persistent threats to organizations in the region. The group’s sustained activity underscores the growing sophistication of cyber threats in Latin America, where Blind Eagle has historically focused on espionage and financial gain. Its reliance on Proton66 highlights the use of resilient hosting services to evade detection. Organizations in the region, particularly government and financial sectors, remain at risk as Blind Eagle adapts its tactics, emphasizing the need for continued vigilance and advanced threat detection measures.
In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.
Key Takeaways
- Blind Eagle threat actor continues evolving toolkit and infrastructure.
- Group moved VBScript delivery to Russian bulletproof hosting Proton66.
- Activity persists with high confidence a year after initial report.