Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Machete

Also known as: APT-C-43, El Machete, Machete, Ragua, machete-apt, G0095

Description

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.(Citation: Cylance Machete Mar 2017)(Citation: Securelist Machete Aug 2014)(Citation: ESET Machete July 2019)(Citation: 360 Machete Sep 2020)

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense

AI Analysis

· 1 week ago

Executive Summary

Machete, also known as APT-C-43 or El Machete, is a Spanish-speaking cyber espionage group targeting government, telecommunications, and defense sectors primarily in Latin America. Known for long-term operations since at least 2010, the group uses sophisticated tactics to compromise high-value organizations. Their activities include spear-phishing, malwares, and persistence techniques, making them a significant threat to global institutions.

Goals & Targeting

Machete's primary motivation is espionage, focusing on intelligence gathering from government and defense sectors. They target high-profile organizations inLatin America and globally, indicating a strategic focus on regions with political or economic interests aligning with their operational goals. Their targeting of telecommunications and power companies suggests an interest in both military and civilian infrastructure for情报 collection and potential disruption.

Enhanced Description

Machete is a suspected Spanish-speaking cyber espionage group active since at least 2010. The group primarily operates in Latin America but has conducted campaigns in the US, Europe, Russia, and parts of Asia. Machete focuses on high-profile targets such as government institutions, intelligence services, military units, telecommunications companies, and power sectors. Their tactics include spear-phishing attacks using malicious links and attachments, drive-by compromises, and the use of legitimate tools like Msiexec and Python for malicious purposes. Over the years, Machete has demonstrated a sustained ability to infiltrate critical infrastructure and gather sensitive information, aligning with their espionage goals. The group's persistence and adaptability make them a persistent threat to targeted industries worldwide.

Key Capabilities

  • Spear-phishing via malicious links and attachments
  • Drive-by compromises
  • Use of legitimate tools like Msiexec, Python, and Windows Command Shell
  • Scheduled task creation for persistence
  • Malicious file distribution
  • Regional focus on Latin America and global targeting

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Defense Evasion
Disruption
Collection

ATT&CK Techniques

T1053.005
T1204.002
T1036.005
T1218.007
T1059.006
T1059.003
T1204.001
T1566.001
T1189

Software / Tooling

Machete malware
Msiexec
Python scripts
Windows Command Shell
Visual Basic scripts

Campaigns & Victims

Machete has been observed in multiple campaigns targeting government and defense sectors since 2010. Their activities include long-term compromises, use of persistence techniques, and regional focus on Latin America. Notable operations have targeted critical infrastructure, with a preference for organizations in Venezuela and other politically significant regions. The group's operational tempo suggests patient, methodical attacks aimed at maximizing intelligence gain over rapid impact.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Malicious Python scripts embedded in legitimate processes
  • Scheduled task creation for persistence
  • Drive-by compromises on targeted websites
  • Use of Msiexec for payload delivery

Recommended Actions

  • Enhance email filtering to detect spear-phishing attempts
  • Monitor for scheduled tasks and unusual process activity
  • Implement endpoint detection solutions to identify malicious scripts
  • Conduct regular network monitoring for C2 traffic patterns
  • Apply patches to mitigate drive-by compromise vulnerabilities
  • Educate employees on phishing attack indicators

Suggested Tags

APT
espionage
government
telecommunications
defense

Confidence Assessment

The data on Machete is moderately reliable with multiple sources corroborating their activities. However, gaps exist in specific campaign details, exact tools used beyond 'Machete', and precise timestamps for first and last seen activity. Additional intelligence sharing could improve understanding of their full capabilities.

ATT&CK Techniques

Execution
6 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Cylance Machete Mar 2017 — The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.
  2. Securelist Machete Aug 2014 — Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.
  3. ESET Machete July 2019 — ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.
  4. 360 Machete Sep 2020 — kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

Intel Summary

11

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

3

Tactics

Tags

APT
Government Targeting
espionage
government
telecommunications
defense

Details

MITRE ID
G0095
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--38863958-a201-4ce1-9dbe-539b0b6804e0
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.