AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Machete
Aliases: APT-C-43, El Machete
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.
Open interactive actor investigation
ATT&CK techniques
Malicious FileT1566.002
Spearphishing LinkT1059.003
Windows Command ShellT1059.005
Visual BasicT1059.006
PythonT1053.005
Scheduled TaskT1036.005
Match Legitimate Name or LocationT1204.001
Malicious LinkT1189
Drive-by CompromiseT1566.001
Spearphishing AttachmentT1218.007
MsiexecT1027
Obfuscated Files or InformationT1025
Data from Removable MediaT1547.001
Registry Run Keys / Startup FolderT1071.001
Web ProtocolsT1074.001
Local Data StagingT1071.002
File Transfer ProtocolsT1568.001
Fast Flux DNS
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModel and dependency supply-chain security
AI Security · explicit-namePrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchDisassembly, decompilation, and code-led analysis
Malware Analysis & Reverse Engineering · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-matchInput boundaries, injection prevention, and safe output
Secure Code & Application Security · topic-matchPolicy architecture, standards, procedures, and exceptions
Governance, Risk & Compliance (GRC) · topic-matchScenario-based cyber risk assessment and treatment
Governance, Risk & Compliance (GRC) · topic-match