Machete

G0095

Threat group.View on attack.mitre.org

About this group

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.

T1053.005
Scheduled Task

Machete has created scheduled tasks to maintain Machete's persistence.

T1059.003
Windows Command Shell

Machete has used batch files to initiate additional downloads of malicious files.

T1059.005
Visual Basic

Machete has embedded malicious macros within spearphishing attachments to download additional files.

T1059.006
Python

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1189
Drive-by Compromise

Machete has distributed Machete through a fake blog website.

T1204.001
Malicious Link

Machete has has relied on users opening malicious links delivered through spearphishing to execute malware.

T1204.002
Malicious File

Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware.

T1218.007
Msiexec

Machete has used msiexec to install the Machete malware.

T1566.001
Spearphishing Attachment

Machete has delivered spearphishing emails that contain a zipped file with malicious contents.

T1566.002
Spearphishing Link

Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives.

Software1

Campaigns0

None recorded.

References4

  1. 360 Machete Sep 2020 Open source
    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.
  2. Cylance Machete Mar 2017 Open source
    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.
  3. ESET Machete July 2019 Open source
    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.
  4. Securelist Machete Aug 2014 Open source
    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.