Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.5
group
Machete G0095
- Created
- 13 September 2019
- Last modified
- 31 July 2026
- Aliases
- Machete · APT-C-43 · El Machete
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0095
Machete has created scheduled tasks to maintain Machete's persistence.6
Machete has used batch files to initiate additional downloads of malicious files.7
Machete has embedded malicious macros within spearphishing attachments to download additional files.8
Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.91011
Machete has distributed Machete through a fake blog website.12
Standing G0095
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
35th percentile · 65% of 176 ATT&CK groups have more Enterprise techniques.
26th percentile · 74% of 176 ATT&CK groups have more tactics spanned.
23rd percentile · 77% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
73rd percentile · 73% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0095
347 distinct rules cover the 11 techniques recorded for this group. The 383 technique-to-rule mappings resolve to 347 distinct rules, because one rule can cover several techniques. 224 Sigma · 123 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org