SYMBOLCOMMON_NAMEaka. SYNONYMS

El Machete  (Back to overview)

aka: APT-C-43, G0095, Machete, machete-apt

El Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successfully, predominantly in Latin America, since 2014. All attackers simply moved to new C2 infrastructure, based largely around dynamic DNS domains, in addition to making minimal changes to the malware in order to evade signature-based detection.


Associated Families
py.pyark win.elmachete_dropper_2022 py.lokirat

References
2023-10-12 ⋅ YouTube (FIRST) ⋅ Aditya K. Sood
"Compromising the Keys to the Kingdom" - Exfiltrating Data to Own and Operate the Exploited Systems
Loki RAT SystemBC
2023-09-12 ⋅ FIRSTCON ⋅ Aditya K. Sood
Compromising the Keys to the Kingdom: Exfiltrating Data to Own and Operate the Exploited Systems (Slides)
Loki RAT SystemBC
2022-03-31 ⋅ Check Point Research
State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
Loki RAT El Machete APT Backdoor Dropper Lyceum .NET DNS Backdoor Lyceum .NET TCP Backdoor Lyceum Golang HTTP Backdoor
2020-09-25 ⋅ 360 Total Security ⋅ kate
APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries - HpReact campaign
PyArk El Machete
2019-09-13 ⋅ MITRE ⋅ MITRE ATT&CK
Machete
El Machete
2019-01-01 ⋅ Council on Foreign Relations ⋅ Cyber Operations Tracker
Machete
El Machete
2017-03-22 ⋅ Cylance ⋅ Threat Research Team
El Machete's Malware Attacks Cut Through LATAM
El Machete
2017-03-22 ⋅ Cylance ⋅ Cylance Threat Research Team
El Machete's Malware Attacks Cut Through LATAM
Machete El Machete
2014-08-20 ⋅ Kaspersky Labs ⋅ GReAT
“El Machete”
Machete El Machete

Credits: MISP Project