The Machete cyberespionage group continued targeting government and military organizations in Latin America, with recent activity focused on Venezuelan government entities and the Ecuadorean military. Researchers observed more than 50 compromised systems communicating with Machete command-and-control infrastructure over a two-month period, while operators exfiltrated gigabytes of confidential data each week. The campaign relied on highly tailored spearphishing emails that used stolen legitimate documents as decoys and reflected detailed knowledge of military communications and target-specific terminology.
The malware toolset, active for years under the names Machete and El Machete, evolved into a more capable Python-based platform with added obfuscation, persistence, geolocation, browser data theft, removable-media collection, and data exfiltration over FTP with HTTP fallback. Reporting across multiple investigations indicates the group has maintained a long-running focus on Latin American targets, and researchers assessed the operators are likely Spanish-speaking and may have a physical presence in one of the affected countries, partly because the malware supports copying stolen data to removable drives.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
ESET disclosed an ongoing cyberespionage campaign by the Machete group that stole gigabytes of confidential data, primarily from Venezuelan government organizations and the Ecuadorean military.
Since May 2019, the operators stopped using separate downloaders and began delivering the decoy document and backdoor components together in the same self-extracting archive.
From late March to late May 2019, ESET observed more than 50 victimized computers actively communicating with Machete command-and-control infrastructure, with most compromised hosts belonging to Venezuelan government organizations.
Since August 2018, Machete components included an additional obfuscation layer using zlib-compressed, base64-encoded text produced with pyminifier, showing further malware hardening.
ESET reported that a new version of the Python-based Machete malware toolset was first seen in April 2018, indicating a significant evolution of the group's capabilities.
Cylance released research describing El Machete malware attacks targeting Latin America, providing another public analysis of the campaign.
Securelist published research on the El Machete malware campaign, marking an early public documentation of the threat actor and its activity in Latin America.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcethreatvector.cylance.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.