Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0409
MITRE ATT&CK Malware

Machete (S0409)

Pyark
ShareXLinkedInRedditHN

[Machete](https://attack.mitre.org/software/S0409) is a cyber espionage toolset used by [Machete](https://attack.mitre.org/groups/G0095). It is a Python-based backdoor targeting Windows machines that was first observed in 2010.(Citation: ESET Machete July 2019)(Citation: Securelist Machete Aug 2014)(Citation: 360 Machete Sep 2020)

Platforms: Windows

▪Techniques implemented (41)

T1140Deobfuscate/Decode Files or InformationT1573.001Symmetric CryptographyT1552.004Private KeysT1041Exfiltration Over C2 ChannelT1070.004File DeletionT1057Process DiscoveryT1125Video CaptureT1027.002Software PackingT1053.005Scheduled TaskT1217Browser Information DiscoveryT1555.003Credentials from Web BrowsersT1132.001Standard EncodingT1071.002File Transfer ProtocolsT1016System Network Configuration DiscoveryT1036.004Masquerade Task or ServiceT1020Automated ExfiltrationT1036.005Match Legitimate Resource Name or LocationT1029Scheduled TransferT1074.001Local Data StagingT1115Clipboard DataT1547.001Registry Run Keys / Startup FolderT1123Audio CaptureT1071.001Web ProtocolsT1010Application Window DiscoveryT1560.003Archive via Custom MethodT1105Ingress Tool TransferT1025Data from Removable MediaT1052.001Exfiltration over USBT1573.002Asymmetric CryptographyT1056.001KeyloggingT1016.002Wi-Fi DiscoveryT1120Peripheral Device DiscoveryT1005Data from Local SystemT1008Fallback ChannelsT1560Archive Collected DataT1059.006PythonT1083File and Directory DiscoveryT1082System Information DiscoveryT1564.001Hidden Files and DirectoriesT1113Screen CaptureT1027.010Command Obfuscation

▪Used by groups (1)

G0095Machete
S0409on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.