Threat Intelligence Tarot
cups · 14
Venezuela / Latin America (suspected state-linked)
G0095
risk 3/5
The Latin Blade
Machete
El Machete
Ecuador militaryColombia militaryNicaragua governmentVenezuela political opponents
Active since ~2010 · Venezuelan foreign policy intelligence, Latin American military espionage, Regional political surveillance
The Latin Blade has cut through Latin American military networks for over a decade - Ecuador's armed forces, Colombia's defense ministry, Nicaragua's government. It is quiet, persistent, and focused on the intelligence needs of its sponsor. It has never made international headlines. That is the point.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
T1566.001
Spearphishing Attachment
Initial Access
T1204.002
Malicious File
Execution
T1056.001
Keylogging
Collection
T1113
Screen Capture
Collection
T1125
Video Capture
Collection
Notable Operations
  • Ecuadorian military targeting - sensitive military documents exfiltrated
  • Decade of operations across Latin American armed forces
  • Spanish-language lures themed around regional political events
  • Custom Python-based implant with keylogging and screen capture
Defenses
Reversed: Their Weakness
Machete's long operational lifespan without significant disruption reflects the low level of cybersecurity investment across many Latin American military organizations - defenders who lack visibility into their own networks cannot find what is hiding in them.

Share this adversary profile

swipe to browse

Data sourced from MITRE ATT&CK. For educational purposes.