Machete
MITRE ATT&CK: S0409 View on attack.mitre.org
Aliases: Pyark, El Machete, Machete
- First seen
- 2010-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:51:01
Targeted industries: government-and-public-sector
Targeted regions: country_code:ve country_code:ec country_code:co
Context
Machete is a cyber espionage toolset used by Machete. It is a Python-based backdoor targeting Windows machines that was first observed in 2010.
Detection coverage
- 1 YARA rules
- 375 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Private Keys (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- File Deletion (attack-pattern)
- Process Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Software Packing (attack-pattern)
- Scheduled Task (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Standard Encoding (attack-pattern)
- File Transfer Protocols (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Scheduled Transfer (attack-pattern)
- Local Data Staging (attack-pattern)
- Clipboard Data (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Audio Capture (attack-pattern)
- Web Protocols (attack-pattern)
- Application Window Discovery (attack-pattern)
- Archive via Custom Method (attack-pattern)
Used by threat actors
- Machete (threat-actor)
Detection rules
- SIGNATURE_BASE_Gen_Python_Pyminifier_Encoded_Payload (yara-rule)
Reports & references
- Kaspersky — 66108 (report)
- cylance.com — El Machete Malware Attacks Cut Through Latam (report)
- blog.360totalsecurity.com — Apt C 43 Steals Venezuelan Military Secrets To Provide Intelligence Support For The Reactionaries Hpreact Campaign (report)
- ESET — Eset Machete (report)
- atomicmatryoshka.com — Infographic Apts In South America (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Machete (report)
- brandefense.io — El Machete Apt Group (report)
- medium.com — El Machete What Do We Know About The Apt Targeting Latin America Be7D11E690E6 (report)
- ESET — Sharpening Machete Cyberespionage (report)
- static1.squarespace.com — Day3 1130 Green A+Study+Of+Machete+Cyber+Espionage+Operations+In+Latin+America (report)
- threatvector.cylance.com — Threat Spotlight Machete Info Stealer (report)
- MITRE ATT&CK — S0409 (report)