Uptime Hamster: 10d 13h 52mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza elcometa

elcometa

0 incidentes 0 paises 0 sectores ransomware CO Ultimo: -
Aliases: SynAck
Ver en IntelTracker → APTTrail →
elcometa, also widely known as Machete, El Machete, and APT-C-43, is a cyber espionage group that has been actively operating since at least 2010. This group is strongly assessed with moderate confidence to be of Venezuelan origin, or at minimum, a Spanish-speaking entity due to the frequent use of Spanish in their malware code, phishing campaigns, and targeted victimology. Their primary motivation is information theft and cyber espionage, with a specific focus on collecting intelligence related to military grids, navigation routes, and Geographic Information Systems (GIS) software files. elcometa is distinguishable by its consistent targeting of Latin American governmental and military entities, leveraging highly tailored spear-phishing emails that often incorporate stolen, authentic classified military documents and military jargon to enhance credibility. The group has also demonstrated a unique capability to exfiltrate stolen data not only through command and control servers but als

Aliases del actor

SynAck

Actores similares

synackransomware · 2
Malware asociado
Machete, Machete
Tecnicas MITRE
T1053.005, T1204.002, T1059.003, T1566.002, T1059.006, T1566.001
Tipo
ransomware
Pais origen
CO
Motivacion
-
Impacto
56
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

ArgentinaBelgiumBolivia, Plurinational State ofBrazilCanadaChileChinaColombiaCubaGermany

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingWholesale TradeTransportation&WarehousingFinanceEducational ServicesOtherPublic AdministrationOil & GasTelecommunications