ATT&CKReferencesCylance Machete Mar 2017

Cylance Machete Mar 2017

The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1025
Data from Removable Media
MalwareMachete

Machete can find, encrypt, and upload files from fixed and removable drives.

T1027.010
Command Obfuscation
MalwareMachete

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1059.006
Python
GroupMachete

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1071.001
Web Protocols
MalwareMachete

Machete uses HTTP for Command & Control.

T1071.002
File Transfer Protocols
MalwareMachete

Machete uses FTP for Command & Control.

T1074.001
Local Data Staging
MalwareMachete

Machete stores files and logs in a folder on the local drive.

T1083
File and Directory Discovery
MalwareMachete

Machete produces file listings in order to search for files to be exfiltrated.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1123
Audio Capture
MalwareMachete

Machete captures audio from the computer’s microphone.

T1125
Video Capture
MalwareMachete

Machete takes photos from the computer’s web camera.

T1204.001
Malicious Link
GroupMachete

Machete has has relied on users opening malicious links delivered through spearphishing to execute malware.

T1204.002
Malicious File
GroupMachete

Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1566.002
Spearphishing Link
GroupMachete

Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives.

T1573.002
Asymmetric Cryptography
MalwareMachete

Machete has used TLS-encrypted FTP to exfiltrate data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.