Overview 38 indicators
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.
| domain | 34 | G0095-domain.txt |
| ipv4 | 2 | G0095.json |
| url | 2 | G0095.json |
Techniques 11 ATT&CK
Open in ATT&CK Navigator → or download the layer (11 techniques, layer 4.5)
- T1036.005 Match Legitimate Resource Name or Location
- T1053.005 Scheduled Task
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1189 Drive-by Compromise
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1218.007 Msiexec
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
Software 1
Principal sources 19 reports
Ranked by how many of this actor's indicators each report brought in.
- 13welivesecurity.com/2019/08/05/sharpening-machete-cyberespi…
- 13welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete…
- 13otx.alienvault.com/pulse/5d4818218a872ad45f4d4e85
- 7research.checkpoint.com/2022/state-sponsored-attack-groups-capi…
- 7otx.alienvault.com/pulse/624c29baad734a210134b02c
- 7securelist.com/el-machete/66108
- 4twitter.com/ShadowChasing1/status/13828695188300390…
- 4twitter.com/ShadowChasing1/status/13828695229656678…
Related groups 3
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 38 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/0xmh1/status/1869632128029442442 · app.validin.com/detail?find=212.224.107.244&type=ip4&re…
pompst.store pumapomp.store skyscopeups.cfd -
app.validin.com/detail?find=43.240.239.76&type=ip4&ref_… · virustotal.com/gui/file/29f8fac13d1500c521ebcd6213e3c4…
funkytothemoon.live -
x.com/ginkgo_g/status/1812766451360731465 · x.com/StrikeReadyLabs/status/1834788474878079… · virustotal.com/gui/file/e936445935c4a636614f7113e41216…
blushaak.co.kr/data/member/resource/ -
research.checkpoint.com/2022/state-sponsored-attack-groups-capi… · otx.alienvault.com/pulse/624c29baad734a210134b02c
domain asymmetricfile.blogspot.com domain correomindefensagobvemyspace.com domain great-jepsen.51-79-62-98.plesk.page domain intelligent-archimedes.51-79-62-98.plesk.page domain postinfomatico.blogspot.com domain solutionconect.online ipv4 31.207.44.72:8080 -
twitter.com/ShadowChasing1/status/13828695188300390… · twitter.com/ShadowChasing1/status/13828695229656678… · virustotal.com/gui/file/813c8b8b43be5a928a5cd841bea08d… · virustotal.com/gui/file/a140a4e60c699dcf110678fca8cfd2…
domain soldatenkovarten.com domain surgutneftegazappstore.com ipv4 31.207.45.243:8080 url http://185.70.187.110 -
securelist.com/el-machete/66108
agaliarept.com blogwhereyou.com frejabe.com grannegral.com java.serveblog.net plushbr.com xmailliwx.com -
virustotal.com/gui/file/825a9c8312acaf025e3389391811d5…
sangeet1.000webhostapp.com -
blog.360totalsecurity.com/en/apt-c-43-steals-venezuelan-military-…
op-icaro.site -
welivesecurity.com/2019/08/05/sharpening-machete-cyberespi… · welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete… · otx.alienvault.com/pulse/5d4818218a872ad45f4d4e85
6e24a5fb.ngrok.io adtiomtardecessd.zapto.org artyomt.com ceofanb18.mipropia.com djcaps.gotdns.ch f9527d03.ngrok.io koliast.com lawyersofficial.mipropia.com mcsi.gotdns.ch tobabean.expert tokeiss.ddns.net u154611594.hostingerapp.com u929489355.hostingerapp.com
Further reading 21
- attack.mitre.org/groups/G0095
- blog.360totalsecurity.com/en/apt-c-43-steals-venezuelan-military-…
- securelist.com/el-machete/66108
- threatvector.cylance.com/en_us/home/el-machete-malware-attacks-c…
- welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete…
- x.com/0xmh1/status/1869632128029442442
- welivesecurity.com/2019/08/05/sharpening-machete-cyberespi…
- virustotal.com/gui/file/813c8b8b43be5a928a5cd841bea08d…
- virustotal.com/gui/file/29f8fac13d1500c521ebcd6213e3c4…
- research.checkpoint.com/2022/state-sponsored-attack-groups-capi…
- app.validin.com/detail?find=43.240.239.76&type=ip4&ref_…
- virustotal.com/gui/file/e936445935c4a636614f7113e41216…
- otx.alienvault.com/pulse/624c29baad734a210134b02c
- x.com/StrikeReadyLabs/status/1834788474878079…
- virustotal.com/gui/file/825a9c8312acaf025e3389391811d5…
- app.validin.com/detail?find=212.224.107.244&type=ip4&re…
- virustotal.com/gui/file/a140a4e60c699dcf110678fca8cfd2…
- twitter.com/ShadowChasing1/status/13828695188300390…
- otx.alienvault.com/pulse/5d4818218a872ad45f4d4e85
- x.com/ginkgo_g/status/1812766451360731465
- twitter.com/ShadowChasing1/status/13828695229656678…