kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareMachete | Machete collects the MAC address of the target computer and other network configuration information. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMachete | Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer. |
| T1053.005 Scheduled Task |
GroupMachete | Machete has created scheduled tasks to maintain Machete's persistence. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1059.003 Windows Command Shell |
GroupMachete | Machete has used batch files to initiate additional downloads of malicious files. |
| T1059.005 Visual Basic |
GroupMachete | Machete has embedded malicious macros within spearphishing attachments to download additional files. |
| T1059.006 Python |
MalwareMachete | Machete is written in Python and is used in conjunction with additional Python scripts. |
| T1059.006 Python |
GroupMachete | Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1083 File and Directory Discovery |
MalwareMachete | Machete produces file listings in order to search for files to be exfiltrated. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1125 Video Capture |
MalwareMachete | Machete takes photos from the computer’s web camera. |
| T1204.002 Malicious File |
GroupMachete | Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware. |
| T1218.007 Msiexec |
GroupMachete | |
| T1566.001 Spearphishing Attachment |
GroupMachete | Machete has delivered spearphishing emails that contain a zipped file with malicious contents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.