ATT&CKReferencesSecurelist Machete Aug 2014

Securelist Machete Aug 2014

Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareMachete

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.

T1052.001
Exfiltration over USB
MalwareMachete

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

T1053.005
Scheduled Task
MalwareMachete

The different components of Machete are executed by Windows Task Scheduler.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1115
Clipboard Data
MalwareMachete

Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events.

T1123
Audio Capture
MalwareMachete

Machete captures audio from the computer’s microphone.

T1125
Video Capture
MalwareMachete

Machete takes photos from the computer’s web camera.

T1132.001
Standard Encoding
MalwareMachete

Machete has used base64 encoding.

T1189
Drive-by Compromise
GroupMachete

Machete has distributed Machete through a fake blog website.

T1204.001
Malicious Link
GroupMachete

Machete has has relied on users opening malicious links delivered through spearphishing to execute malware.

T1204.002
Malicious File
GroupMachete

Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1566.001
Spearphishing Attachment
GroupMachete

Machete has delivered spearphishing emails that contain a zipped file with malicious contents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.