El_Machete__2019__blog_Sharpening_the_Machete.pdf
ID: fab6dcb9-c71d-4548-803a-afa63c20a4b1
STIX ID: report--fab6dcb9-c71d-4548-803a-afa63c20a4b1
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-08-06
Last Modified Date: 2019-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes an active, targeted cyberespionage campaign (Machete) against military and government organizations in Latin America that uses spearphishing with self‑extracting archives to deliver obfuscated Python/py2exe backdoors. The malware family includes downloader, persistence (GoogleCrash.exe), spy (Chrome.exe) and communication (GoogleUpdate.exe) components capable of screenshots, keylogging, browser data theft, geolocation via Mozilla Location Service, collection of GIS and cryptographic files, and exfiltration to FTP/Dropbox/Google Docs or removable drives; more than 50 infected hosts (mostly Venezuelan military) were observed, with gigabytes of data exfiltrated weekly.
