logo

El_Machete__2019__blog_Sharpening_the_Machete.pdf

ID: fab6dcb9-c71d-4548-803a-afa63c20a4b1

STIX ID: report--fab6dcb9-c71d-4548-803a-afa63c20a4b1

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2019-08-06

Last Modified Date: 2019-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes an active, targeted cyberespionage campaign (Machete) against military and government organizations in Latin America that uses spearphishing with self‑extracting archives to deliver obfuscated Python/py2exe backdoors. The malware family includes downloader, persistence (GoogleCrash.exe), spy (Chrome.exe) and communication (GoogleUpdate.exe) components capable of screenshots, keylogging, browser data theft, geolocation via Mozilla Location Service, collection of GIS and cryptographic files, and exfiltration to FTP/Dropbox/Google Docs or removable drives; more than 50 infected hosts (mostly Venezuelan military) were observed, with gigabytes of data exfiltrated weekly.