Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Blind Eagle Hackers Target Government Agencies Using PowerShell Scripts

Colombian government institutions have been targeted by a sophisticated cyberattack campaign orchestrated by the BlindEagle threat group. This operation involved the use of compromised internal email accounts, PowerShell scripts, and steganography to…

Colombian government institutions have been targeted by a sophisticated cyberattack campaign orchestrated by the BlindEagle threat group. This operation involved the use of compromised internal email accounts, PowerShell scripts, and steganography to deploy remote access trojans on targeted systems, as identified by Zscaler ThreatLabz researchers.

The spear-phishing operation was uncovered in early September 2025, revealing that BlindEagle targeted agencies under Colombia's Ministry of Commerce, Industry, and Tourism (MCIT). The attackers utilized an email sent from a compromised account within the same organization, enabling them to bypass traditional email security controls such as DMARC, DKIM, and SPF checks, exploiting institutional trust in the process.

ThreatLabz analysis indicates that the phishing email originated from a legitimate Microsoft 365 server authorized by the organization’s SPF policy, with all message trajectory headers appearing authentic. This attack highlights BlindEagle’s shift from deploying single-malware campaigns to orchestrating complex, multi-layer attack chains involving the Caminho downloader and DCRAT remote access trojan.

The campaign began with a legal-themed phishing email, impersonating Colombia's judicial system, complete with fabricated case numbers and urgent demands for receipt confirmation. The message contained an SVG image attachment that, when clicked, decoded a Base64-encoded HTML page mimicking an official Colombian judicial web portal.

Victims interacting with the fraudulent portal would automatically download a JavaScript file initiating a file-less attack sequence. The malware executed three JavaScript code snippets using integer array deobfuscation techniques, with each stage reconstructing and launching subsequent payloads. The third JavaScript stage introduced Unicode-based comments and complex string manipulation to evade detection before executing a PowerShell command via Windows Management Instrumentation.

Colombian government institutions have been targeted by a sophisticated cyberattack campaign orchestrated by the BlindEagle threat group.
Paige Monroe · Thehackingpost

The PowerShell script downloaded an image file from the Internet Archive containing a Base64-encoded payload hidden between specific markers labeled "BaseStart-" and "-BaseEnd." Using steganography to conceal malicious code, the script carved out the embedded assembly, decoded it, and dynamically loaded it as a .NET module using reflection techniques.

ThreatLabz identified the loaded assembly as Caminho, a downloader malware first observed in Brazilian cybercriminal marketplaces in May 2025. Evidence suggests Portuguese-speaking developers created Caminho, as the malware’s primary method contains argument names in Portuguese.

BlindEagle adopted Caminho early, using it to download DCRAT payloads from Discord content delivery networks. The final-stage DCRAT malware employed process hollowing techniques, launching the legitimate MSBuild.exe utility and injecting malicious code directly into memory. This AsyncRAT variant features AES-256 encrypted configurations and certificate-based command-and-control server authentication functionality absent from DCRAT’s original open-source codebase.

Advertisement

ThreatLabz discovered 24 hosts worldwide exposing certificates matching the DCRAT sample’s issuer, with infrastructure primarily hosted on Swedish IP addresses under ASN 42708 (GleSYS AB), a hosting provider historically favored by BlindEagle. The group also utilized Dynamic DNS services from ydns.eu, consistent with previously documented operational patterns.

The campaign is attributed to BlindEagle with medium confidence based on infrastructure preferences, Colombian targeting, legal-themed lures, extensive use of .NET malware, legitimate service abuse including Discord for payload hosting, and documented steganography techniques. The attack highlights BlindEagle’s persistent focus on Colombian government entities and demonstrates the group’s adoption of sophisticated tools from underground marketplaces to enhance operational capabilities.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories