ATT&CKReferences360 Machete Sep 2020

360 Machete Sep 2020

kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMachete

Machete collects the MAC address of the target computer and other network configuration information.

T1036.005
Match Legitimate Resource Name or Location
GroupMachete

Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.

T1053.005
Scheduled Task
GroupMachete

Machete has created scheduled tasks to maintain Machete's persistence.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1059.003
Windows Command Shell
GroupMachete

Machete has used batch files to initiate additional downloads of malicious files.

T1059.005
Visual Basic
GroupMachete

Machete has embedded malicious macros within spearphishing attachments to download additional files.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1059.006
Python
GroupMachete

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1071.001
Web Protocols
MalwareMachete

Machete uses HTTP for Command & Control.

T1071.002
File Transfer Protocols
MalwareMachete

Machete uses FTP for Command & Control.

T1083
File and Directory Discovery
MalwareMachete

Machete produces file listings in order to search for files to be exfiltrated.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1123
Audio Capture
MalwareMachete

Machete captures audio from the computer’s microphone.

T1125
Video Capture
MalwareMachete

Machete takes photos from the computer’s web camera.

T1204.002
Malicious File
GroupMachete

Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware.

T1218.007
Msiexec
GroupMachete

Machete has used msiexec to install the Machete malware.

T1566.001
Spearphishing Attachment
GroupMachete

Machete has delivered spearphishing emails that contain a zipped file with malicious contents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.