Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The accidental infection of an attacker's workstation with a consumer infostealer exposed the entire infrastructure, RATs, and phishing kits of a campaign linked to the Blind Eagle group targeting Colombia. The investigative breakthrough, documented by LevelBlue in a report published today, turned a single operational security failure into a complete map of GitHub repositories, C2 domains, lure templates, and email delivery tools. The dossier demonstrates how attacker operational security can collapse over a mundane mistake: using the same machine to run campaigns and browse the internet.
- A malware investigation exposed the tools and infrastructure of operators suspected in a Blind Eagle-linked campaign targeting Colombia, revealing the fragility of their operational security.
- The breakthrough came after an attacker workstation was infected by a separate infostealer, leaving a record of its activity in publicly accessible stolen-data logs.
- Recovered material showed browser history, local folders, and credentials from a device associated with the campaign's operational path, including a 'Rats' folder with AsyncRAT, DcRat, Remcos, and XWorm builds.
- The verified attack chain exploited self-extracting archives with cleartext passwords in email bodies, obfuscated VBScript and PowerShell, and final abuse of InstallUtil.exe, a signed Windows utility.
How the Infostealer Betrayed the Operator
The investigation broke open when a consumer infostealer infected the attacker's workstation. The program left a complete record of its activity in a collection of stolen-data logs, according to the cited source. LevelBlue traced a GitHub commit email address to this log, linking an apparently anonymous digital identity to a physically compromised device.
The operational email address appears in the ALIEN TXTBASE stealer log collection and is independently associated with a computer compromised by an infostealer named 'Ghost.' Have I Been Pwned confirms the address across six breaches. The exposed data included browser history, local folders, and credentials, providing a snapshot of the campaign's operational workflow.
The LevelBlue report states: "The findings do not prove a person's identity. Instead, they map the workflow behind the attacks." This limitation is methodologically significant: digital exposure does not equal judicial identification, but it makes the criminal ecosystem readable.
"The break came after an apparent attacker workstation was infected by a separate information-stealing program, leaving a record of its activity" — LevelBlue report via CyberSecurityNews
The Modular Architecture of Colombian Phishing
The GitHub account cabeto850128 hosted parts of a loader that separated the legitimate AutoIt interpreter from the script logic, a staging technique that makes static detection harder. Additional repositories such as comicsam and jacobo contained raw payloads with .pif extensions and .html configuration files, documented in the report's IOC tables.
The operator's machine contained HTML and Word templates mimicking Colombian judicial and traffic notification themes. Victims were directed to password-protected archives, a technique that reduces automated email scanning and delays detection. The report documents that the password appeared in cleartext in the message body, a detectable behavioral pattern.
SendBlaster bulk-email software, a mass-delivery tool, had an external relay configured and logged a test delivery to the same operational email address. This elementary error — testing infrastructure on themselves — created a link between the actor and the campaign.
The Multi-Stage Chain and Abuse of Signed Utilities
The verified attack chain follows a deliberately complex path. Self-extracting archives launched obfuscated VBScript and PowerShell, which wrote content to ProgramData, a legitimate system directory. The final stage reached InstallUtil.exe, a Microsoft-signed Windows utility that can be abused to execute malicious code.
The use of legitimate components — techniques commonly described as LOLBAS — allows bypassing digital signature checks and confusing detection systems. Correlated samples contacted code repositories and cloud storage, illustrating why a reputable hosting name is not a safety signal. Abused platforms included Bitbucket, AWS S3, and Discord, distributing single-point-of-failure risk and making delivery resilient.
Browser history showed activity on hosting, email marketing, file storage, and obfuscation services, outlining an operational workflow that mixed commercial and criminal tools without clear architectural separation.
The RAT Arsenal and Payload Interchangeability
A folder labeled 'Rats' contained builds and artifacts linked to four remote-access tools: AsyncRAT, DcRat, Remcos, and XWorm. The presence of this collection, according to the cited source, "suggests the operator could change payloads, instead of depending on one malware family or delivery route." This modularity is a hallmark of operational maturity: the actor was not locked into a single toolkit but could adapt infrastructure to different targets or countermeasures.
C2 domains used dynamic services like duckdns.org, enabling rapid endpoint changes without registering new domain names. The combination of four RATs, interchangeable templates, and flexible delivery infrastructure indicates an operation designed to persist and scale, not a limited one-off attack.
What to Do Now
Recommendations derive directly from patterns observed in the campaign. LevelBlue states: "Organizations should flag messages carrying password-protected archives when the password appears in the email body." This specific pattern — cleartext password accompanied by a protected archive — is a detectable behavioral indicator at the gateway filtering level.
Security teams should monitor for abuse of InstallUtil.exe and similar signed utilities in non-administrative contexts. The documented chain — self-extracting archive, VBScript, PowerShell, ProgramData, InstallUtil.exe — forms a sequence detectable with EDR behavioral rules.
The exposure of public GitHub repositories as raw payload staging requires monitoring of raw.githubusercontent.com and analogous services in proxy logs. The presence of .pif extensions and .html configuration files in these paths is a documented IOC pattern in the report.
The campaign demonstrates that impersonation of Colombian judicial entities and traffic authorities is a recurring vector. Anti-phishing filters for the Colombian public sector should include these specific themes in detection models.
Conclusion
The LevelBlue investigation turns an attacker's operational error into a systemic lesson for defenders. The same modularity that made the campaign resilient — four RATs, interchangeable templates, multiple cloud platforms — made the infrastructure exposed when a single endpoint fell. The case does not prove the operator's identity, but it maps their workflow with precision: a result more useful for collective defense than an uncertain judicial conviction.
The key numerical datum remains six: the breaches confirming the operational email address on Have I Been Pwned, the thread that unraveled the entire tapestry. For defenders, the lesson is that attackers share the same attack surface as their targets — and sometimes the same recklessness.
Information is based on the cited source and current as of publication.
Sources
- https://cybersecuritynews.com/hackers-own-malware-infection/
- https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis/
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
- https://thehackernews.com/2026/03/north-korean-hackers-publish-26-npm.html
- https://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/
- https://thehackernews.com/2026/03/threatsday-bulletin-pqc-push-ai-vuln.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-33053
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://thehackernews.com/2025/06/microsoft-patches-67-vulnerabilities.html
- https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.