Machete, also referred to as Pyark, is a Python-based espionage malware toolset associated with the Machete threat group. It has been used primarily in cyberespionage operations targeting high-profile organizations in Latin America, especially Venezuelan government entities and the Ecuadorean military, with affected sectors including military, education, police, and foreign affairs. The malware has been distributed through highly tailored spearphishing emails that used compressed self-extracting archives and decoy documents, including legitimate documents previously stolen from victims, to induce execution.
On compromised Windows systems, Machete provides broad surveillance and collection capabilities. It captures screenshots, logs keystrokes, inspects running processes to identify web browsers, steals stored credentials from multiple browsers, gathers clipboard and browser profile data, and collects host and network configuration details including MAC address and related network information. It also derives victim geolocation by collecting nearby Wi-Fi data and processing it through external geolocation services. Machete monitors for newly inserted devices via Windows messaging and searches removable media for files of interest.
The malware is designed for document theft and targeted collection. It searches local file systems for sensitive files, including office documents, backups, databases, cryptographic material, and GIS-related data, and can retrieve specific files on operator request. It also supports execution of additional binaries downloaded from command-and-control infrastructure. Collected data is exfiltrated over the command-and-control channel, primarily using FTP, with HTTP implemented as a fallback transport. Machete has used Base64 for obfuscation and AES to protect exfiltrated and downloaded data. After successful upload, it can delete local copies of stolen files to reduce forensic visibility.
For persistence and execution, Machete has used Windows Task Scheduler, and it has also used the Windows startup folder. Later variants incorporated heavier obfuscation and packaging changes, including self-extracting archives containing Python components rather than only py2exe-built executables. Overall, Machete is a mature espionage backdoor focused on long-term collection, credential theft, surveillance, and resilient exfiltration against government and military targets in Latin America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET has been tracking a new version of Machete (the group’s Python-based toolset) that was first seen in April 2018.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Defense Evasion T1027 Obfuscated Files or Information Python scripts are obfuscated.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Collection T1056 Input Capture Machete logs keystrokes from the victim’s machine.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Discovery T1010 Application Window Discovery Window names are reported along with keylogger information.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Discovery T1049 System Network Connections Discovery Netsh command is used to list all nearby Wi-Fi networks.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Collection T1025 Data from Removable Media Files are copied from newly inserted drives.
Collection T1056 Input Capture Machete logs keystrokes from the victim’s machine.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Command and Control T1071 Standard Application Layer Protocol FTP is used for Command & Control.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Exfiltration T1020 Automated Exfiltration All collected files are exfiltrated automatically via FTP to remote servers.
Exfiltration T1029 Scheduled Transfer Data is sent to the C&C server every 10 minutes.
85 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Machete ... (v2.1→v2.2) ...
Machete (v2.1→v2.2)
Collects target MAC address and other network configuration information.
Malware that exfiltrates collected data over the same channel used for command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.