LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0409: Machete

Machete is a cyber espionage toolset used by Machete. It is a Python-based backdoor targeting Windows machines that was first observed in 2010.[1][2][3]

EnterpriseS0409MalwareObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Machete is a Windows-focused, Python-based backdoor/toolset associated in ATT&CK with cyber espionage activity. Its decision value is not a single malware signature; it is the operating pattern shown by its ATT&CK relationships: discovery, collection, staging, command-and-control, scheduled execution, removable-media collection/exfiltration, and credential-risk behaviors such as keylogging. For leaders, this matters most where sensitive documents, government or regulated data, military/telecom-style operations, or disconnected/USB-dependent environments are business-critical.

Executive priority

Treat Machete as a coverage-validation scenario for espionage-style data theft on Windows endpoints. Priority questions: Can the organization prove it monitors Python/script execution, suspicious scheduled tasks, data staging, removable media activity, and outbound web/file-transfer channels? Are USB and sensitive-data controls auditable? Can IR teams reconstruct what was collected and exfiltrated if a backdoor used fallback C2 or scheduled transfers? This is especially relevant to resilience, compliance evidence, and cyber-physical/air-gapped risk where removable media is part of operations.

Technical view

ATT&CK lists Machete as a Python-based Windows backdoor used by group G0095. No official detection guidance is provided, so defenders should validate coverage against the related techniques rather than depend on a named-malware rule. Key validation areas include Python execution on Windows, scheduled task creation or masquerading, application/process/system/network/Wi-Fi discovery, local and removable-media data collection, local staging, file deletion, command obfuscation, packed software, web and file-transfer C2, fallback channels, and exfiltration over C2, scheduled transfer, or USB.

Likely telemetry

  • Windows endpoint process creation and command-line/script execution logs, especially Python-related execution
  • Scheduled task creation, modification, execution, names, descriptions, and parent processes
  • File system activity showing collection, staging directories, unusual file access, and deletion
  • Removable media and USB connection, file access, and data movement records
  • Network telemetry for outbound web protocols and file-transfer protocols such as FTP where collected

Detection direction

  • Build detections around behavior clusters: Python execution plus discovery plus staging or outbound transfer is higher value than any one event alone.
  • Review scheduled tasks for suspicious naming, masquerading, unusual locations, unexpected interpreters, or recurrence patterns aligned to scheduled transfer behavior.
  • Correlate removable media activity with sensitive file access and outbound network transfer, especially in environments that rely on USB for operational workflows.
  • Tune web and file-transfer protocol monitoring to identify unusual destinations, timing, volume, or hosts, while accounting for legitimate administrative and business file movement.
  • Hunt for local staging followed by file deletion, since cleanup can reduce forensic visibility.

Mitigation priorities

  • Prioritize endpoint visibility on Windows systems: process, script, scheduled task, file, removable media, and network telemetry.
  • Restrict and monitor unauthorized Python/script execution where business use does not require it.
  • Govern scheduled tasks with change control, logging, and review of task names, paths, and run contexts.
  • Apply least-privilege and data access controls to reduce the value of local collection and keylogging-derived credentials.
  • Control removable media use with policy, logging, and approval workflows, especially for sensitive or operational networks.
Additional notes and limits

The supplied ATT&CK object identifies Machete as a Python-based Windows backdoor/toolset first observed in 2010 and used by the Machete group. The most useful defensive interpretation comes from the listed relationships to techniques spanning collection, discovery, command-and-control, execution, persistence, stealth, credential access, and exfiltration.

Official ATT&CK detection is not provided, and the object itself has no specified tactics, aliases, or labels. This take does not include indicators of compromise, active exploitation claims, or environment-specific exposure. Local telemetry, asset criticality, data flows, and approved USB/Python usage are required to determine actual risk and detection quality.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Machete

Machete is a cyber espionage toolset used by Machete. It is a Python-based backdoor targeting Windows machines that was first observed in 2010.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

41 rows
DomainIDNameRelationship / procedure
EnterpriseT1140Deobfuscate/Decode Files or Information

Machete’s downloaded data is decrypted using AES.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Machete has used AES to exfiltrate documents.[1]

EnterpriseT1552.004Private KeysSub-technique

Machete has scanned and looked for cryptographic keys and certificate file extensions.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Machete's collected data is exfiltrated over the same channel used for C2.[1]

EnterpriseT1070.004File DeletionSub-technique

Once a file is uploaded, Machete will delete it from the machine.[1]

EnterpriseT1057Process Discovery

Machete has a component to check for running processes to look for web browsers.[1]

EnterpriseT1125Video Capture

Machete takes photos from the computer’s web camera.[2][4][3]

EnterpriseT1027.002Software PackingSub-technique

Machete has been packed with NSIS.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

The different components of Machete are executed by Windows Task Scheduler.[1][2]

EnterpriseT1217Browser Information Discovery

Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Machete collects stored credentials from several web browsers.[1]

EnterpriseT1132.001Standard EncodingSub-technique

Machete has used base64 encoding.[2]

EnterpriseT1071.002File Transfer ProtocolsSub-technique

Machete uses FTP for Command & Control.[1][4][3]

EnterpriseT1016System Network Configuration Discovery

Machete collects the MAC address of the target computer and other network configuration information.[1][3]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks.[1]

EnterpriseT1020Automated Exfiltration

Machete’s collected files are exfiltrated automatically to remote servers.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.[1][2]

EnterpriseT1029Scheduled Transfer

Machete sends stolen data to the C2 server every 10 minutes.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Machete stores files and logs in a folder on the local drive.[1][4]

EnterpriseT1115Clipboard Data

Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events.[1][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Machete used the startup folder for persistence.[2][4]

EnterpriseT1123Audio Capture

Machete captures audio from the computer’s microphone.[2][4][3]

EnterpriseT1071.001Web ProtocolsSub-technique

Machete uses HTTP for Command & Control.[1][4][3]

EnterpriseT1010Application Window Discovery

Machete saves the window names.[1]

EnterpriseT1560.003Archive via Custom MethodSub-technique

Machete's collected data is encrypted with AES before exfiltration.[1]

EnterpriseT1105Ingress Tool Transfer

Machete can download additional files for execution on the victim’s machine.[1]

EnterpriseT1025Data from Removable Media

Machete can find, encrypt, and upload files from fixed and removable drives.[4][1]

EnterpriseT1052.001Exfiltration over USBSub-technique

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.[1][2]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Machete has used TLS-encrypted FTP to exfiltrate data.[4]

EnterpriseT1056.001KeyloggingSub-technique

Machete logs keystrokes from the victim’s machine.[1][2][4][3]

EnterpriseT1016.002Wi-Fi DiscoverySub-technique

Machete uses the netsh wlan show networks mode=bssid and netsh wlan show interfaces commands to list all nearby WiFi networks and connected interfaces.[1]

EnterpriseT1120Peripheral Device Discovery

Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message.[1]

EnterpriseT1005Data from Local System

Machete searches the File system for files of interest.[1]

EnterpriseT1008Fallback Channels

Machete has sent data over HTTP if FTP failed, and has also used a fallback server.[1]

EnterpriseT1560Archive Collected Data

Machete stores zipped files with profile data from installed web browsers.[1]

EnterpriseT1059.006PythonSub-technique

Machete is written in Python and is used in conjunction with additional Python scripts.[1][2][3]

EnterpriseT1083File and Directory Discovery

Machete produces file listings in order to search for files to be exfiltrated.[1][4][3]

EnterpriseT1082System Information Discovery

Machete collects the hostname of the target computer.[1]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive.[1]

EnterpriseT1113Screen Capture

Machete captures screenshots.[1][2][4][3]

EnterpriseT1027.010Command ObfuscationSub-technique

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.[4][1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0095: Machete

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
602a1fb25b198313...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.2Current bundle602a1fb25b19…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  2. [2]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  3. [3]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  4. [4]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  5. [5]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  6. [6]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  7. [7]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  8. [8]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  9. [9]
    Machete

    (Citation: Securelist Machete Aug 2014)

  10. [10]
    Machete

    (Citation: Securelist Machete Aug 2014)

  11. [11]
    Machete

    (Citation: Securelist Machete Aug 2014)

  12. [12]
    Pyark

    (Citation: 360 Machete Sep 2020)

  13. [13]
    Pyark

    (Citation: 360 Machete Sep 2020)

  14. [14]
    Pyark

    (Citation: 360 Machete Sep 2020)

  15. [15]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  16. [16]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  17. [17]
    mitre-attackS0409
    Open source URL
  18. [18]
    mitre-attackS0409
    Open source URL
  19. [19]
    mitre-attackS0409
    Open source URL
  20. [20]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  21. [21]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  22. [22]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  23. [23]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  24. [24]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  25. [25]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  26. [26]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  27. [27]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  28. [28]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  29. [29]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  30. [30]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  31. [31]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  32. [32]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  33. [33]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  34. [34]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  35. [35]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  36. [36]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  37. [37]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  38. [38]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  39. [39]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  40. [40]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  41. [41]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  42. [42]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  43. [43]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  44. [44]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  45. [45]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  46. [46]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  47. [47]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  48. [48]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  49. [49]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  50. [50]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  51. [51]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  52. [52]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  53. [53]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  54. [54]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  55. [55]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  56. [56]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  57. [57]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  58. [58]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  59. [59]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  60. [60]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  61. [61]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  62. [62]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  63. [63]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  64. [64]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  65. [65]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  66. [66]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  67. [67]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  68. [68]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  69. [69]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  70. [70]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  71. [71]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  72. [72]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  73. [73]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  74. [74]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  75. [75]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  76. [76]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  77. [77]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  78. [78]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  79. [79]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  80. [80]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  81. [81]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  82. [82]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  83. [83]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  84. [84]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  85. [85]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  86. [86]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  87. [87]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  88. [88]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  89. [89]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  90. [90]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  91. [91]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  92. [92]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  93. [93]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  94. [94]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  95. [95]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  96. [96]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  97. [97]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  98. [98]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  99. [99]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  100. [100]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  101. [101]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  102. [102]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  103. [103]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  104. [104]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  105. [105]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  106. [106]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  107. [107]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  108. [108]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  109. [109]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  110. [110]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  111. [111]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  112. [112]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  113. [113]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  114. [114]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  115. [115]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  116. [116]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  117. [117]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  118. [118]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  119. [119]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  120. [120]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  121. [121]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  122. [122]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  123. [123]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  124. [124]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  125. [125]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  126. [126]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  127. [127]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  128. [128]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  129. [129]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  130. [130]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  131. [131]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  132. [132]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  133. [133]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  134. [134]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  135. [135]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  136. [136]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  137. [137]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  138. [138]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  139. [139]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  140. [140]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  141. [141]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  142. [142]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  143. [143]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  144. [144]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  145. [145]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  146. [146]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  147. [147]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  148. [148]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  149. [149]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.