TAG-144's Persistent Grip on South American Organizations

Aug. 26, 2025, 7:38 p.m.

Description

Insikt Group has identified five distinct activity clusters linked to TAG-144 (Blind Eagle), targeting primarily Colombian government entities across local, municipal, and federal levels throughout 2024 and 2025. The clusters share similar tactics, techniques, and procedures (TTPs) such as using open-source and cracked remote access trojans (RATs), dynamic domain providers, and legitimate internet services (LIS) for staging. However, they differ in infrastructure, malware deployment, and operational methods. The group maintains an extensive operational infrastructure, employs various RATs, and uses multi-stage infection chains. TAG-144's primary focus appears to be credential theft and espionage, with evidence linking it to Red Akodon and compromised Colombian government email accounts used in spearphishing campaigns.

Date

  • Created: Aug. 26, 2025, 3:21 p.m.
  • Published: Aug. 26, 2025, 3:21 p.m.
  • Modified: Aug. 26, 2025, 7:38 p.m.

Attack Patterns

  • BlotchyQuasar
  • BitRAT
  • LV
  • Bladabindi
  • Njw0rm
  • REMCOS RAT
  • njRAT - S0385
  • LimeRAT
  • DcRAT
  • QuasarRAT
  • XWorm
  • AsyncRAT
  • TAG-144

Additional Informations

  • Healthcare
  • Energy
  • Defense
  • Education
  • Finance
  • Government
  • Manufacturing
  • Panama
  • Chile
  • Colombia
  • Ecuador