Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
3 malware familiesExploits CVEs in the wild

Careto

Also known asCaretothe_mask

Careto, also known as The Mask, is a highly sophisticated cyber-espionage threat actor active since at least 2007. The content describes it as a likely state-sponsored or nation-state actor, including references to it being a Spanish-speaking nation-state group and Kaspersky’s assessment that it could be state-sponsored based on its sophistication and operational behavior. Historically, Careto has targeted high-profile organizations including governments, diplomatic entities, embassies, research institutions, energy and oil and gas companies, private equity firms, and activists. The group is associated with advanced and modular malware for Windows and Mac OS X, as well as rootkit and bootkit capabilities; command-and-control artifacts also suggested possible Linux, Android, and iOS implants. Initial infections were delivered through spear-phishing emails linking to malicious websites, including use of Adobe Flash Player exploit CVE-2012-0773, as well as social-engineering lures involving Java and Chrome plugin installation. The malware collected sensitive files and credentials, including encryption keys, VPN configurations, SSH keys, RDP files, certificates, and other document and email-related data. The content also notes adversary tools associated with Careto searching compromised systems for cryptographic keys and certificate files. Kaspersky’s original public reporting stated that Careto infrastructure was taken offline in January 2014, but later research linked intrusions from 2019, 2022, and early 2024 to the actor with medium to high confidence. In a 2019 intrusion, the actor used the Careto2 and Goreto frameworks. Careto2 used a plugin-based architecture, virtual file system storage, scheduled-task execution, and COM hijacking for persistence; identified plugins included ConfigMgr.dll, FileFilter.dll, Storage.dll, Kodak.dll, and Comm.dll, with Comm.dll uploading exfiltrated data to attacker-controlled OneDrive storage. Goreto, a Golang toolset, periodically connected to Google Drive to retrieve commands and supported file download/upload, command execution, keylogging, and screenshot capture. In a 2022 intrusion against a Latin American organization, the actor compromised an MDaemon email server and abused the WorldClient extension mechanism for persistence by modifying WorldClient.ini and configuring malicious CgiBase6/CgiFile6 entries. The malicious extension supported reconnaissance, file-system interaction, and execution of additional payloads. For lateral movement and persistence, the attackers used scheduled tasks and abused the legitimate HitmanPro Alert driver hmpalert.sys to load a malicious hmpalert.dll into privileged processes such as winlogon.exe and dwm.exe. Kaspersky named the resulting implant FakeHMP, which could retrieve files, log keystrokes, take screenshots, and deploy further payloads; the attackers also deployed a microphone recorder and file stealer. In early 2024, the same hmpalert.sys abuse was observed again against another victim, this time using a Google Updater-based technique instead of scheduled tasks. Attribution in the recent cases was based on overlaps with historical The Mask activity, including victimology, file names, plugin naming conventions, persistence methods, virtual file systems, cloud storage usage, process propagation techniques, and repeated use of the installer file ~dfae01202c5f0dba42.cmd.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Academia & Research
MITRE ATT&CK

Tradecraft

26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics39 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1189
Drive-by Compromise
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
5 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.003
Windows Command Shell
T1203
Exploitation for Client Execution
T1204
User Execution
T1574
Hijack Execution Flow
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1505
Server Software Component
T1505.003
Web Shell
T1542
Pre-OS Boot
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
TA0005
Stealth
6 techniques
T1014
Rootkit
T1055
Process Injection
T1070
Indicator Removal
T1211
Exploitation for Stealth
T1542
Pre-OS Boot
T1574
Hijack Execution Flow
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1649×2
Steal or Forge Authentication Certificates
TA0007
Discovery
2 techniques
T1082
System Information Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1570
Lateral Tool Transfer
TA0009
Collection
4 techniques
T1005×2
Data from Local System
T1056
Input Capture
T1056.001
Keylogging
T1113
Screen Capture
T1123
Audio Capture
TA0011
Command and Control
1 technique
T1105×2
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping26

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.