Frequently Asked Questions

Threat Details: BlindEagle APT & QuasarRAT

What is the BlindEagle APT group and which regions have they targeted?

The BlindEagle APT group (APT-C-36) is an advanced persistent threat actor known for targeting victims in Colombia and Ecuador. Their campaigns have involved sophisticated phishing emails designed to appear as official communications from government entities in these countries. Note: Detailed information about their activities outside Colombia and Ecuador is not documented in the provided sources.

How does the BlindEagle APT deliver QuasarRAT to victims?

The BlindEagle APT uses phishing emails with subject lines crafted to appear as official government communications. These emails contain shortened URL links and PDF attachments with the same link. When the link is clicked, a compressed and password-protected LHA archive is downloaded, containing QuasarRAT. The malware is only deployed if the request originates from Colombia; otherwise, the infection process is terminated. Note: The infection chain may vary in other campaigns or regions.

What additional tools and techniques did BlindEagle use in their Ecuador and Colombia campaigns?

In addition to QuasarRAT, BlindEagle used RAR files containing executable Python scripts that spawn the Windows binary MSHTA to retrieve further payloads. These scripts perform system checks, disable anti-malware and behavior detection software, and eventually load an in-memory Meterpreter payload. Note: The effectiveness of these techniques may depend on the victim's security controls and configurations.

Cymulate Platform: Features & Capabilities

How can Cymulate help organizations defend against threats like BlindEagle APT and QuasarRAT?

Cymulate is an AI-powered cyber defense engineering platform that enables organizations to continuously validate, prioritize, and improve their cyber defenses against real threats and exposures. Key features include exposure validation, automated mitigation, continuous threat exposure management, and a comprehensive threat library. Cymulate can simulate phishing, malware, and advanced persistent threat scenarios similar to those used by BlindEagle, helping organizations identify and remediate vulnerabilities before they are exploited. Note: Cymulate's effectiveness depends on proper configuration and ongoing use; it is not a replacement for all security controls.

What types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios to ensure comprehensive security validation. Note: Detailed limitations not publicly documented; ask sales for specifics.

What is Cymulate's Immediate Threats Module and how does it benefit users?

The Immediate Threats Module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The module's effectiveness depends on timely updates and user engagement.

Use Cases & Business Impact

What business impact can organizations expect from using Cymulate?

Organizations using Cymulate have reported an average 30% increase in threat prevention, a 90% improvement in threat detection, and a 52% reduction in critical exposures. Teams also experience a 60% boost in efficiency and 40X faster threat validation compared to manual methods. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months (case study). Note: Results may vary based on organizational maturity and implementation.

Who can benefit from using Cymulate?

Cymulate is designed for a range of roles, including CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, Vulnerability Management Teams, GRC/Compliance Teams, and IT/Infrastructure/Cloud Teams. It is suitable for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Note: Organizations with highly specialized or legacy environments may require additional customization.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, operating in an agentless mode that eliminates the need for additional hardware or complex configurations. Users can start running simulations almost immediately, with only basic infrastructure and internet connectivity required. The platform features an intuitive dashboard and offers comprehensive support via email and chat. Note: Large-scale or highly regulated environments may require additional onboarding steps.

What do customers say about Cymulate's ease of use?

Customers consistently praise Cymulate for its ease of use and intuitive design. For example, Raphael Ferreira, Cybersecurity Manager, stated: "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Other users highlight its user-friendly portal, actionable insights, and suitability for both technical and non-technical stakeholders. Note: Some organizations may require additional training for advanced features.

Security, Compliance & Integrations

What security and compliance certifications does Cymulate have?

Cymulate holds SOC2 Type II certification, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1. These certifications cover information security management, privacy, cloud security, and compliance with the Cloud Controls Matrix. Note: For the latest certification status, refer to Cymulate's security overview page.

What integrations does Cymulate support?

Cymulate integrates with over 50 security tools, including SIEM platforms (Azure Sentinel, Splunk, CrowdStrike Falcon LogScale), EDR and anti-malware solutions (CrowdStrike Falcon, Carbon Black EDR, Cisco Secure Endpoint), cloud security tools (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella), vulnerability management (Rapid7 InsightVM), and others such as Microsoft Defender, Palo Alto Networks, Wiz, and Zscaler. Note: Integration availability may vary by package and environment.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to each organization's needs. Pricing depends on the selected package, number of assets, and chosen scenarios and features. For a tailored quote, organizations are encouraged to schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed and may vary significantly by organization size and requirements.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. AttackIQ is a direct competitor but does not offer the same breadth of daily updates or the AI Copilot feature. Cymulate is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may be preferred by organizations with existing investments in their ecosystem. Note: Cymulate does not disclose all feature differences publicly; ask for a detailed comparison if needed.

How does Cymulate compare to Mandiant Security Validation?

Cymulate emphasizes continuous innovation with AI and automation, rapid deployments, and an intuitive dashboard. Mandiant Security Validation is also a leader in the space but may require more manual customization and has a different approach to attack library updates. Cymulate provides daily updates and actionable remediation guidance. Mandiant may be preferred by organizations already using other Mandiant or Google Cloud products. Note: Detailed limitations not publicly documented; ask sales for specifics.

Technical Documentation & Resources

Where can I find technical documentation and resources about Cymulate?

Cymulate provides a comprehensive resource hub at https://cymulate.com/resources/, including industry reports, whitepapers, case studies, and technical guides. Specific resources include the Threat Studio data sheet and the Detection Engineering Automation Guide. Note: Some resources may require registration or a Cymulate account.

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

BlindEagle APT Targets Ecuador And Columbia With Sharpened Tools Including QuasarRAT

January 8, 2023

The BlindEagle APT group (APT-C-36) has been targeting victims in Columbia and Ecuador in an ongoing phishing campaign used to deliver the QuasarRAT.
The emails contain subject lines that made them appear to be from the Colombian Government, the email contained both a shortened URL link as well as a PDF attachment that contained the same link.
Upon clicking the shortened link, a compressed and password protected file with an LHA (archive) extension was downloaded which contained the QuasarRAT that was unpacked and deployed to the machine, however if the request was made from a machine originating from outside of Colombia the infection process is terminated.
In an additional campaign, Ecuador and Columbia were both targeted with phishing emails and subject lines made to appear to be from the Ecuadorian Government.
The campaign was more elaborate in that the threat used delivered a RAR file that contained an executable python file that was spawn the Windows binary MSHTA to retrieve additional payloads, scripts that would perform system checks, disable anti malware/behavior detection software, and eventually load an in-memory Meterpreter payload