Home Cyber Security News BlindEagle Leveraging PowerShell to Infiltrate Government Infrastructure

BlindEagle Leveraging PowerShell to Infiltrate Government Infrastructure

0
BlindEagle PowerShell attack

Zscaler’s ThreatLabz team has uncovered a new spear-phishing campaign launched by BlindEagle, a South American-based cyber espionage group known for targeting institutions in Spanish-speaking nations.

The latest attack, detected in early September 2025, targeted a Colombian government agency within the Ministry of Commerce, Industry, and Tourism (MCIT).

Compromised Accounts and Fraudulent Web Portal

The campaign began with a phishing email that appeared to originate within the same organization, likely from a compromised Microsoft 365 account.

By abusing internal trust, the email bypassed DMARC, DKIM, and SPF checks. Disguised as an official message from Colombia’s judicial system, the email referenced a fake labor lawsuit and included an SVG attachment.

When clicked, the SVG image is decoded into an HTML page that mimics an authentic judicial web portal.

After a few seconds, this webpage automatically downloaded a JavaScript file named ESCRITO JUDICIAL…js. Opening this file triggered a multistage infection chain comprising nested JavaScript and PowerShell scripts.

Each JavaScript stage was obfuscated using arrays of integers and encoded strings to conceal its purpose.

 BlindEagle attack chain
 BlindEagle attack chain

The final script used Windows Management Instrumentation (WMI) to execute a PowerShell command in a stealthy, file-less manner.

The PowerShell script downloaded an image from the Internet Archive, extracted hidden Base64 data embedded between the markers BaseStart- and -BaseEnd, and decoded it directly in memory as a .NET assembly.

Multi-Layered Delivery: Caminho and DCRAT

The payload extracted by PowerShell was identified as Caminho, a malware downloader associated initially with the Brazilian cybercriminal community.

Caminho, also known as VMDetectLoader, retrieved its next-stage payload from a Discord URL via an obfuscated Base64-Encoded string. The payload, hidden in AGT27.txt, was decoded and injected into MSBuild.exe via process hollowing.

The final stage deployed DCRAT, an open-source Remote Access Trojan (RAT) built in C#. DCRAT enables extensive control over infected systems, including keylogging, disk access, and plugin execution.

It includes AMSI bypass techniques to evade antivirus detection and uses AES-256 encryption and certificate-based authentication for secure command-and-control (C2) communication.

Zscaler linked the campaign to BlindEagle based on infrastructure overlaps, consistent targeting of Colombian institutions, and the reuse of Portuguese-language malware components.

The group is known to host payloads on legitimate platforms, such as Discord, and to employ steganography to hide data.

This attack demonstrates BlindEagle’s ongoing evolution from simple, single-malware infections to layered, multi-phase intrusions that leverage PowerShell, in-memory loaders, and open-source RATs.

Government agencies in Latin America remain high-priority targets, underscoring the need for enhanced email security and behavioral threat detection to counter such sophisticated phishing threats.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version