Machete

S0409

Malware.View on attack.mitre.org

About this malware

Machete is a cyber espionage toolset used by Machete. It is a Python-based backdoor targeting Windows machines that was first observed in 2010.

Techniques used41

Procedure examples41

TechniqueProcedure example
T1005
Data from Local System

Machete searches the File system for files of interest.

T1008
Fallback Channels

Machete has sent data over HTTP if FTP failed, and has also used a fallback server.

T1010
Application Window Discovery

Machete saves the window names.

T1016
System Network Configuration Discovery

Machete collects the MAC address of the target computer and other network configuration information.

T1016.002
Wi-Fi Discovery

Machete uses the netsh wlan show networks mode=bssid and netsh wlan show interfaces commands to list all nearby WiFi networks and connected interfaces.

T1020
Automated Exfiltration

Machete’s collected files are exfiltrated automatically to remote servers.

T1025
Data from Removable Media

Machete can find, encrypt, and upload files from fixed and removable drives.

T1027.002
Software Packing

Machete has been packed with NSIS.

T1027.010
Command Obfuscation

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1029
Scheduled Transfer

Machete sends stolen data to the C2 server every 10 minutes.

T1036.004
Masquerade Task or Service

Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks.

T1036.005
Match Legitimate Resource Name or Location

Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.

T1041
Exfiltration Over C2 Channel

Machete's collected data is exfiltrated over the same channel used for C2.

T1052.001
Exfiltration over USB

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

T1053.005
Scheduled Task

The different components of Machete are executed by Windows Task Scheduler.

View all 41 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. 360 Machete Sep 2020 Open source
    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.
  2. ESET Machete July 2019 Open source
    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.
  3. Securelist Machete Aug 2014 Open source
    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.