Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMachete | Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables. |
| T1052.001 Exfiltration over USB |
MalwareMachete | Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| T1053.005 Scheduled Task |
MalwareMachete | The different components of Machete are executed by Windows Task Scheduler. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1059.006 Python |
MalwareMachete | Machete is written in Python and is used in conjunction with additional Python scripts. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1115 Clipboard Data |
MalwareMachete | Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1125 Video Capture |
MalwareMachete | Machete takes photos from the computer’s web camera. |
| T1132.001 Standard Encoding |
MalwareMachete | Machete has used base64 encoding. |
| T1189 Drive-by Compromise |
GroupMachete | Machete has distributed Machete through a fake blog website. |
| T1204.001 Malicious Link |
GroupMachete | Machete has has relied on users opening malicious links delivered through spearphishing to execute malware. |
| T1204.002 Malicious File |
GroupMachete | Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMachete | Machete used the startup folder for persistence. |
| T1566.001 Spearphishing Attachment |
GroupMachete | Machete has delivered spearphishing emails that contain a zipped file with malicious contents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.