ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Machete

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Machete

NamesMachete
El Machete
CategoryMalware
TypeReconnaissance, Backdoor, Info stealer, Credential stealer
DescriptionAccording to ESET, Machete’s dropper is a RAR SFX executable. Three py2exe components are dropped: GoogleCrash.exe, Chrome.exe and GoogleUpdate.exe. A single configuration file, jer.dll, is dropped, and it contains base64-encoded text that corresponds to AES-encrypted strings.
GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence.
Regarding the geolocation of victims, Chrome.exe collects data about nearby Wi-Fi networks and sends it to the Mozilla Location Service API. In short, this application provides geolocation coordinates when it’s given other sources of data such as Bluetooth beacons, cell towers or Wi-Fi access points. Then the malware takes latitude and longitude coordinates to build a Google Maps URL.
The GoogleUpdate.exe component is responsible for communicating with the remote C&C server. The configuration to set the connection is read from the jer.dll file: domain name, username and password. The principal means of communication for Machete is via FTP, although HTTP communication was implemented as a fallback in 2019.
Information<https://www.welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete.pdf>
<https://securelist.com/el-machete/66108/>
<https://www.cylance.com/en_us/blog/el-machete-malware-attacks-cut-through-latam.html>
<https://medium.com/@verovaleros/el-machete-what-do-we-know-about-the-apt-targeting-latin-america-be7d11e690e6>
MITRE ATT&CK<https://attack.mitre.org/software/S0409/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.machete>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:Machete>

Last change to this tool card: 13 May 2020

Download this tool card in JSON format

Previous: LZ77
Next: Madi

All groups using tool Machete

ChangedNameCountryObserved

APT groups

 El Machete[Unknown]2010-Jun 2020 

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key