Also known as: APT-C-43, El Machete, Machete, Ragua, machete-apt, G0095
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.(Citation: Cylance Machete Mar 2017)(Citation: Securelist Machete Aug 2014)(Citation: ESET Machete July 2019)(Citation: 360 Machete Sep 2020)
Targeted Sectors
Executive Summary
Machete, also known as APT-C-43 or El Machete, is a Spanish-speaking cyber espionage group targeting government, telecommunications, and defense sectors primarily in Latin America. Known for long-term operations since at least 2010, the group uses sophisticated tactics to compromise high-value organizations. Their activities include spear-phishing, malwares, and persistence techniques, making them a significant threat to global institutions.
Goals & Targeting
Machete's primary motivation is espionage, focusing on intelligence gathering from government and defense sectors. They target high-profile organizations inLatin America and globally, indicating a strategic focus on regions with political or economic interests aligning with their operational goals. Their targeting of telecommunications and power companies suggests an interest in both military and civilian infrastructure for情报 collection and potential disruption.
Enhanced Description
Machete is a suspected Spanish-speaking cyber espionage group active since at least 2010. The group primarily operates in Latin America but has conducted campaigns in the US, Europe, Russia, and parts of Asia. Machete focuses on high-profile targets such as government institutions, intelligence services, military units, telecommunications companies, and power sectors. Their tactics include spear-phishing attacks using malicious links and attachments, drive-by compromises, and the use of legitimate tools like Msiexec and Python for malicious purposes. Over the years, Machete has demonstrated a sustained ability to infiltrate critical infrastructure and gather sensitive information, aligning with their espionage goals. The group's persistence and adaptability make them a persistent threat to targeted industries worldwide.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Machete has been observed in multiple campaigns targeting government and defense sectors since 2010. Their activities include long-term compromises, use of persistence techniques, and regional focus on Latin America. Notable operations have targeted critical infrastructure, with a preference for organizations in Venezuela and other politically significant regions. The group's operational tempo suggests patient, methodical attacks aimed at maximizing intelligence gain over rapid impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Machete is moderately reliable with multiple sources corroborating their activities. However, gaps exist in specific campaign details, exact tools used beyond 'Machete', and precise timestamps for first and last seen activity. Additional intelligence sharing could improve understanding of their full capabilities.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
11
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
3
Tactics