El Machete has targeted Latin American government and military sectors since 2014.
Analyst brief
El Machete is a threat actor active since 2014, primarily targeting government and military sectors across Latin America and other regions. The group gains initial access via Spearphishing Link and Drive-by Compromise, deploying the Machete malware through Windows Command Shell. To evade detection, they utilize stealth techniques like masquerading as legitimate resource names and abusing Msiexec. Defenders should monitor network traffic to dynamic DNS-based C2 infrastructure and educate users on targeted phishing campaigns.
El Machete
Machetemachete-aptAPT-C-43
unknown
El Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successfully, predominantly in Latin America, since 2014. All attackers simply moved to new C2 infrastructure, based largely around dynamic DNS domains, in addition to making minimal changes to the malware in order to evade signature-based detection.
Analyze process creation and command-line logging to detect process names masquerading as Legitimate Resource Name or Location and suspicious use of Msiexec.
FAQ2
What tactics does the El Machete group use for initial access?+
The El Machete group uses Spearphishing Link and Drive-by Compromise tactics for initial access.
What techniques does the El Machete group apply to evade detection?+
The El Machete group masquerades as legitimate resource names and abuses system tools like Msiexec to evade detection.