NEW: Group Profiler — instant APT intel lookup. Try it →

Machete

G0095 Espionage MITRE ATT&CK →

Also known as: APT-C-43 · El Machete

Overview

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.

Naming & attribution

Machete is tracked under 3 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2010.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
APT-C-43kate
El MacheteThe Cylance Threat Research Team
MacheteKaspersky Global Research and Analysis Team

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Rancor — 6 shared techniques (43% overlap)
  • Transparent Tribe Pakistan — 7 shared techniques (39% overlap)
  • Molerats — 7 shared techniques (35% overlap)
  • Elderwood China — 5 shared techniques (33% overlap)
  • Mofang China — 4 shared techniques (31% overlap)
  • FIN4 — 5 shared techniques (28% overlap)

Targets

Government · Military

Regions

Belgium · Brazil · China · Colombia · Cuba · Ecuador · France · Germany · Malaysia · Peru · Russia · Spain · Sweden · United States · Venezuela

TTPs — 11 techniques across 3 tactics

Initial Access

Execution

Tools & malware (1)

Machete

Reporting (3)