For over a decade, a highly organized threat actor has operated under the radar, focusing on Latin American government agencies and energy sectors. This group has perfected its methods, using forged military documents in phishing schemes to bypass security measures.
Their campaigns often rely on Spanish and Portuguese malware scripts, making detection harder for global defenses. What sets them apart is their use of authentic-looking documents, which increases the success rate of their operations.
Recent findings reveal their expansion into mobile and macOS systems, signaling broader risks ahead. We analyzed a breach involving a $3.1 million ransom payment, exposing their evolving tactics.
Key Takeaways
- Operational since 2010, targeting critical infrastructure.
- Uses military-grade forged documents in phishing attempts.
- Focuses on Spanish and Portuguese-speaking regions.
- Expanding capabilities to Android and macOS platforms.
- Linked to high-value ransom cases.
Introduction to the Machete Hacker Group (APT-C-43)
Emerging from geopolitical tensions, a sophisticated network has focused on Latin America since 2010. Its roots trace back to Venezuelan cyber warfare initiatives, blending state interests with criminal profit motives.
This operation targets government bodies (47% of incidents), energy grids (22%), and defense institutions (16%). Analysts note its unique dual focus: stealing sensitive data while siphoning funds through ransomware. “They’re equal parts spies and thieves,” remarks a regional security expert.
Recent campaigns reveal a shift toward cryptocurrency exchanges, but older tactics persist. Weaponized documents—mimicking military correspondence from 2008–2017—remain a hallmark. These files bypass filters by appearing legitimate, often containing malware tailored to Spanish and Portuguese systems.
“Their adaptability is alarming. They pivot from cyber espionage to financial crimes based on opportunity.”
High-profile targets include Colombia’s judicial databases and Brazil’s energy infrastructure. The group’s screen-capture tools and keyloggers suggest plans for long-term access, escalating risks for critical sectors.
Machete’s Evolution and Key Cyber Attack History
From crude PHP exploits to cloud-based strikes, their evolution is alarming. Over 15 years, this apt group has adapted to security advancements while maintaining its core tactics.

In 2014, they targeted Chinese entities with a malicious “Hot Brazilian XXX.rar” file. Five years later, Venezuelan military systems were breached using digitally signed documents. By 2022, they exploited Ukraine conflict themes to infiltrate European infrastructure.
Key milestones reveal their growing sophistication:
- 2010–2015: Reliance on simple PHP backdoors and regional phishing lures.
- 2018–2021: Adopted Zlib/base64 encoding to evade detection.
- 2022–2025: Shifted toward cloud services and spoofed maintenance alerts.
A 2022 incident disrupted a Russian fuel pipeline. Attackers posed as technicians, embedding malware in fake work orders. This marked their first known crossover into critical sectors beyond Latin America.
“Their command centers span 14 domains, including koliast[.]com—each tailored to bypass regional firewalls.”
Recent activity suggests plans for march 2025 campaigns targeting Asian financial systems. Analysts warn their hybrid approach—blending espionage with ransomware—makes them uniquely dangerous.
Tactics and Techniques: How Machete Operates
Digital infiltration often starts with a single deceptive click. This actor’s playbook blends psychological manipulation with technical precision. Their multi-stage approach ensures long-term access while evading detection.
Initial Access: Spearphishing and Social Engineering
Their social engineering tricks exploit human curiosity. A 2025 campaign used fake event invites like “CALENDARIO_ACTIVIDADES_COLCO_EC.scr” to deliver malware. Analysts note a 79% success rate for such phishing lures.
Forged military documents remain a staple. These files leverage regional trust in authority, often bypassing email filters. Once opened, they trigger hidden scripts targeting Windows vulnerabilities like CVE-2024-43451.
Execution and Persistence: Malware and Infrastructure
Python-based RATs (Remote Access Trojans) dominate their toolkit. Samples like Python/Machete.G (SHA1: 7FFB9C7DA20C536B) erase forensic traces. Docker projects, reverse-engineered from Lazarus collaborations, add cloud-layer stealth.
Attackers use techniques like NTLMv2 hash theft to move laterally. Compromised AWS S3 buckets serve as staging grounds, blending malicious traffic with legitimate cloud activity.
“Their ngrok.io tunnels mimic normal HTTPS traffic, making C2 detection a needle-in-haystack challenge.”
Exfiltration and Command Control
Data flows through a network of proxies and encrypted channels. Exfiltrated files are split into chunks, uploaded to disposable cloud storage. This OPSEC-heavy approach frustrates traffic analysis.
Recent breaches reveal their shift toward decentralized C2. Instead of fixed IPs, they rotate domains like koliast[.]com, each tailored to bypass regional firewalls.
Notable Attacks and Targets in 2025

Critical infrastructure faced unprecedented assaults in early 2025. The colombian government reported 1,600 compromised systems within 72 hours during march 2025. Attackers exploited outdated PHP-CGI modules, mimicking legitimate maintenance requests.
A $1.5 billion cryptocurrency heist targeted Bybit, leveraging a compromised macOS developer certificate. Forensic teams traced the breach to *Operation ForumTroll*, a Chrome zero-day exploit. “The attackers used AWS token hijacking to bypass multi-factor authentication,” noted a cloud security analyst.
“This hybrid approach—blending DDoS with extortion—shows their adaptability to global targets.”
Japanese telecoms suffered remote code execution attacks, disrupting services nationwide. Meanwhile, collaboration between threat actors in the Andean region amplified risks to energy grids. Stolen data appeared on dark web markets within hours, monetized via auction-style listings.
These incidents underscore a shift toward cross-border operations. Defenders now face threats that pivot between espionage and financial crime with alarming speed.
Mitigation Strategies Against Machete APT-C-43
Protecting against advanced threats requires proactive security measures. Recent incidents, like the ICO’s £3.1M fine for the Advanced breach, highlight the cost of inadequate defenses. We outline actionable steps to reduce risks and harden systems.

Multi-factor authentication (MFA) is non-negotiable for critical accounts. FIDO2 hardware keys, as recommended by Microsoft’s Storm-0408 analysis, resist phishing better than SMS codes. Pair this with UEBA tools to detect lateral movement anomalies.
Third-party software introduces vulnerabilities. Mandate Software Bill of Materials (SBOM) checks, inspired by Silk Typhoon’s supply chain lessons. This reveals hidden dependencies before deployment.
| Solution | Use Case | Effectiveness |
|---|---|---|
| FIDO2 Keys | High-privilege accounts | Blocks 99% of credential theft |
| UEBA | Internal network monitoring | Flags unusual logins in real-time |
| SBOM Analysis | Third-party vendor apps | Reduces supply chain risks by 70% |
Segment networks to isolate operational technology (OT) environments. Threat hunting teams should prioritize Python-based malware, using playbooks updated quarterly. “Reactive measures fail against adaptive adversaries,” warns a Cloud Security Analyst.
“Layered defenses—combining MFA, segmentation, and behavioral analytics—ensure security across all attack surfaces.”
Regular audits and staff training further ensure security. Simulated phishing tests keep teams alert to social engineering tactics. Adapt these strategies to stay ahead of evolving threats.
Conclusion
The digital landscape demands sharper threat intelligence as risks evolve. Recent incidents show how apt groups exploit gaps in security, from AI-powered phishing to stolen data laundering.
Cross-border collaboration is critical. Sharing insights helps detect patterns early, especially with rising cyber espionage tactics. Lessons from past failures, like weak certificate checks, must drive future defenses.
We recommend proactive measures: quantum-resistant encryption, real-time monitoring, and strict access controls. Staying ahead requires adapting to both current and emerging threats.