Machete
MITRE ATT&CK: G0095 View on attack.mitre.org
Aliases: APT-C-43, El Machete, Machete, machete-apt
- First seen
- 2010-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:53:11
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:ve country_code:us country_code:ru
Context
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.
Detection coverage
- 1 YARA rules
- 164 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Spearphishing Link (attack-pattern)
- Windows Command Shell (attack-pattern)
- Visual Basic (attack-pattern)
- Python (attack-pattern)
- Scheduled Task (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Malicious Link (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Msiexec (attack-pattern)
- Machete (malware)
Reports & references
- MITRE ATT&CK — G0095 (report)
- Kaspersky — 66108 (report)
- cylance.com — El Machete Malware Attacks Cut Through Latam (report)
- cfr.org — Machete (report)
- threatvector.cylance.com — El Machete Malware Attacks Cut Through Latam (report)
- blog.360totalsecurity.com — Apt C 43 Steals Venezuelan Military Secrets To Provide Intelligence Support For The Reactionaries Hpreact Campaign (report)
- ESET — Eset Machete (report)