El_Machete__2020__apt-c-43-steals-venezuelan-military-secrets-to-provide-intelligence-support-for-the-reactionaries-hpreact-campaign.pdf
ID: 5c33554f-3878-4a24-811a-82e3e9a55dfe
STIX ID: report--5c33554f-3878-4a24-811a-82e3e9a55dfe
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-09-28
Last Modified Date: 2020-09-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Total Security reports on the HpReact espionage campaign attributed to APT-C-43 (linked to Machete) that targeted Venezuelan military institutions since 2019. Attackers used spearphishing with malicious Word macros to retrieve an FTP-downloaded batch script and an MSI deployer which installs a Python-based backdoor (Fpyark/Pyark) under %ProgramData%\USOEnable; the backdoor collects documents, captures keystrokes, screenshots, webcam images and audio, and exfiltrates data via FTP. The report includes code excerpts, deployment details, persistence mechanisms (scheduled task, startup lnk), IoCs (MD5s, IPs, FTP usernames/paths) and a timeline of observed toolset changes.
