Machete

MITRE ATT&CK: G0095 View on attack.mitre.org

Aliases: APT-C-43, El Machete, Machete, machete-apt

First seen
2010-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:53:11

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:ve country_code:us country_code:ru

Context

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.

Detection coverage

  • 1 YARA rules
  • 164 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Visual Basic (attack-pattern)
  • Python (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Malicious Link (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Msiexec (attack-pattern)
  • Machete (malware)

Reports & references

  • MITRE ATT&CK — G0095 (report)
  • Kaspersky — 66108 (report)
  • cylance.com — El Machete Malware Attacks Cut Through Latam (report)
  • cfr.org — Machete (report)
  • threatvector.cylance.com — El Machete Malware Attacks Cut Through Latam (report)
  • blog.360totalsecurity.com — Apt C 43 Steals Venezuelan Military Secrets To Provide Intelligence Support For The Reactionaries Hpreact Campaign (report)
  • ESET — Eset Machete (report)

External references