The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1025 Data from Removable Media |
MalwareMachete | Machete can find, encrypt, and upload files from fixed and removable drives. |
| T1027.010 Command Obfuscation |
MalwareMachete | Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1059.006 Python |
GroupMachete | Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1074.001 Local Data Staging |
MalwareMachete | Machete stores files and logs in a folder on the local drive. |
| T1083 File and Directory Discovery |
MalwareMachete | Machete produces file listings in order to search for files to be exfiltrated. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1125 Video Capture |
MalwareMachete | Machete takes photos from the computer’s web camera. |
| T1204.001 Malicious Link |
GroupMachete | Machete has has relied on users opening malicious links delivered through spearphishing to execute malware. |
| T1204.002 Malicious File |
GroupMachete | Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMachete | Machete used the startup folder for persistence. |
| T1566.002 Spearphishing Link |
GroupMachete | Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives. |
| T1573.002 Asymmetric Cryptography |
MalwareMachete | Machete has used TLS-encrypted FTP to exfiltrate data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.