The Careto (also known as The Mask) threat actor conducted a long-running cyber-espionage campaign that targeted government, diplomatic, energy, research, private equity, and activist organizations in at least 31 countries. Researchers linked the operation to more than 1,000 IP addresses and identified at least 380 unique victims. Initial compromise commonly began with spear-phishing emails that directed targets to malicious websites exploiting vulnerabilities such as Adobe Flash Player CVE-2012-0773, alongside social-engineering lures involving fake Java and Chrome plugin updates.
The malware platform was notably advanced and modular, with Windows and Mac OS X implants, rootkit and bootkit functionality, and suspected Linux and mobile components. It was designed to steal sensitive files and credentials, including encryption keys, VPN configurations, SSH keys, RDP files, and a wide range of documents, while also using stealth techniques that included a customized attack against older Kaspersky products. Kaspersky reported that the group’s known command-and-control infrastructure went offline after January 2014 and said it sinkholed several servers for telemetry, detecting known samples as Trojan.Win32/Win64.Careto.* and Trojan.OSX.Careto.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Securelist published a frequently asked questions article summarizing known details of the Careto campaign, including at least 380 unique victims across 31 countries and more than 1,000 observed IP addresses. The post also noted Kaspersky detection names for known variants.
During the campaign, victims were infected through spear-phishing emails linking to malicious websites that served exploits, including Adobe Flash Player CVE-2012-0773, along with social-engineering lures involving Java and Chrome plugin installation. The malware platform included advanced Windows and Mac OS X implants, with suspected Linux and mobile components.
Kaspersky reported that all known Careto command-and-control servers were offline after January 2014, indicating the operators shut down their infrastructure. Kaspersky also sinkholed several servers to collect telemetry on the campaign.
Kaspersky described Careto (also known as The Mask) as a highly sophisticated cyber-espionage threat actor active since at least 2007. The campaign targeted government, diplomatic, energy, research, private equity, and activist entities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceschneier.com
Open sourcemashable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.