Careto, also known as The Mask, is a sophisticated cyber-espionage malware platform and associated intrusion set active since at least 2007 and publicly exposed in 2014, with later activity linked to the same operators observed again in 2019, 2022, and 2024. It has been assessed as a likely state-sponsored operation and has been reported as internally suspected by some researchers to be linked to Spain, although public attribution has remained cautious. The operation has targeted government institutions, embassies, diplomatic organizations, energy and oil and gas companies, research institutions, private equity entities, and activists across dozens of countries, with notable victimization in Latin America, North Africa, Europe, and Cuba in particular.
The platform is notable for its breadth, modularity, and operational maturity. Historical reporting identified Windows and macOS implants, a rootkit, a bootkit, and indications of Linux as well as possible Android and iOS components. Careto infections were commonly initiated through spearphishing links themed around news and political topics, including impersonation of Spanish media, with victims redirected to legitimate sites after exploitation. Observed delivery also included exploitation of Adobe Flash Player vulnerability CVE-2012-0773 and social-engineering lures involving browser plugins or fake software updates. In later operations, the operators also maintained access through a compromised email server component and used DLL sideloading and abuse of a legitimate security driver to achieve persistence and broad process injection.
Careto’s capabilities center on covert surveillance and intelligence collection. Reported functions include keylogging, screenshot capture, theft of files and sensitive documents, collection of encryption material such as PGP keys, SSH keys, VPN configurations, browsing history, cookies, login data, and interception of communications including internet traffic and voice conversations. Later linked tooling also supported microphone recording while suppressing user-facing microphone indicators, cloud-based exfiltration, modular plugin execution, command execution, file operations, reconnaissance, and lateral movement inside victim networks. Historical second-stage components such as SGH expanded surveillance and file-monitoring functions, while later linked frameworks including Careto2, Goreto, and FakeHMP showed continued use of modular implants, reflective loading, COM hijacking, scheduled-task deployment, and cloud storage services for command-and-control and exfiltration.
Careto has also demonstrated strong defense-evasion tradecraft. The operators used stealthy persistence, digitally signed samples in some periods, anti-forensic cleanup, and rapid infrastructure teardown after public exposure in 2014, including wiping logs rather than simply deleting them. The malware was also reported to have attempted to exploit an older vulnerability in Kaspersky products to conceal itself on infected systems. This combination of multi-platform tooling, deep surveillance capability, disciplined operational security, and long-term victim targeting has made Careto one of the more prominent espionage malware operations documented from its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These include at least one Adobe Flash Player exploit (CVE-2012-0773). The exploit was designed for Flash Player versions prior to 10.3 and 11.2. | What exactly is Careto / “The Mask”? The Mask is an advanced threat actor that has been involved in cyber-espionage operations since at least 2007. What makes The Mask special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated piece of malware, a rootkit, a bootkit, Mac OS X and Linux versions and possibly versions for Android and iPad/iPhone (iOS).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The compromise of the infected machine started with deployment of Careto2.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious website contains a number of exploits designed to infect the visitor, depending on his system configuration. Upon successful infection, the malicious website redirects the user to the benign website referenced in the e-mail.
When clicking on these malicious links, the victim would get infected using an exploit that hacked the user’s specific device, then redirected to a legitimate web page so as to not raise suspicions.
This includes an extremely sophisticated piece of malware, a rootkit, a bootkit... Detection is extremely difficult because of stealth rootkit capabilities.
The Careto group relied in large part on spearphishing emails that contained malicious links impersonating Spanish newspapers like El País, El Mundo, and Público
the Careto hackers shut down all of its operations discovered by the Russian firm, going as far as wiping its logs
The Mask also uses a customized attack against older Kaspersky Lab products in order to hide in the system.
its stealthy malware capable of stealing highly sensitive data, including private conversations and keystrokes from the computers it compromised...
The malware collects a large list of documents from the infected system, including encryption keys, VPN configurations, SSH keys and RDP files.
its stealthy malware capable of stealing highly sensitive data, including private conversations and keystrokes from the computers it compromised...
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of a set of advanced malware families known for sophisticated engineering and espionage capability.
Named malware/platform referenced with aliases The Mask, Mask, and Ugly Face.
Advanced espionage malware used in long-running intrusions against government institutions, embassies, diplomatic organizations, energy companies, research institutions, private companies, and activists. Capabilities described include stealing sensitive files and keystrokes, intercepting internet traffic and Skype conversations, collecting PGP keys and VPN configurations, taking screenshots, activating the microphone covertly, harvesting session cookies and browsing history, and deploying implants functioning as a backdoor, keylogger, and screenshot tool across Windows, macOS, Linux, with possible Android and iPhone targeting.
A highly sophisticated, modular cyber-espionage malware platform with Windows and Mac OS X trojans and suspected Linux, Android, and iOS components. It intercepts communications, steals sensitive files and credentials such as encryption keys, VPN configurations, SSH keys, and RDP files, supports additional malicious modules, and uses stealth features including rootkit and bootkit capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.