Machete: Dissecting the Operations of a Cyber Espionage Group in Latin America

Jun 20, 2019·
Veronica Valeros
Maria Rigaki
Maria Rigaki
,
Sebastian Garcia
· 0 min read
Abstract
Reports on cyber espionage operations have been on the rise in the last decade. However, operations in Latin America are heavily under researched and potentially underestimated. In this paper we analyze and dissect a cyber espionage tool known as Machete. Our research shows that Machete is operated by a highly coordinated and organized group who focuses on Latin American targets. We describe the five phases of the APT operations from delivery to exfiltration of information and we show why Machete is considered a cyber espionage tool. Furthermore, our analysis indicates that the targeted victims belong to military, political, or diplomatic sectors. The review of almost six years of Machete operations show that it is likely operated by a single group, and their activities are possibly statesponsored. Machete is still active and operational to this day
Type
Publication
IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 464–473
Status
Peer-reviewed
publications
Maria Rigaki
Authors
Postdoctoral Researcher

Maria Rigaki is a post-doctoral researcher in the Department of Computer Science at the Czech Technical University in Prague. As a member of the Stratosphere Lab, she works on the security and privacy of machine learning, and on applications of AI in cyber security. Before that she spent many years as a software developer and systems architect, working on telecommunications, physical security, emergency response systems and critical infrastructure.

In her spare time Maria enjoys hacking and playing with guitars.