Kaspersky researchers reported that Careto (also known as The Mask), a sophisticated cyber-espionage group believed dormant since 2014, has continued operating through at least 2024. Newly linked intrusions were identified in 2019, 2022, and January 2024, including a 2022 breach of a Latin American organization via an MDaemon email server and deployment of a malware implant dubbed FakeHMP. The newer operations abused the legitimate hmpalert.sys driver to load a malicious hmpalert.dll for persistence, keylogging, screenshot capture, command execution, and cloud exfiltration through OneDrive; other components stole browser, messenger, and organizational files, while a separate DLL covertly recorded microphone audio and uploaded MP3 files to Dropbox. A distinct 2019 intrusion used the Careto2 and Goreto frameworks, COM hijacking for persistence, modular plugins, and Google Drive for command-and-control and data theft.
The activity was tied to the historic Careto operation with medium to high confidence based on overlaps in victimology, filenames, plugin naming, modular design, and persistence techniques seen in the group’s earlier campaigns targeting governments, embassies, diplomatic entities, energy firms, research institutions, and activists across 31 countries. TechCrunch separately reported that several former Kaspersky employees believed with high confidence that Careto was run by hackers working for the Spanish government, though Kaspersky did not publicly make that attribution and Spain declined to comment. The group’s malware has been noted for broad surveillance capabilities across Windows, macOS, and Linux, including theft of keystrokes, files, cookies, browsing histories, PGP keys, VPN configurations, screenshots, and microphone audio, with Cuba described as a particularly significant historical target.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
TechCrunch reported that several former Kaspersky employees believed with high confidence that Careto was operated by hackers working for the Spanish government. The article said Kaspersky had not made that attribution publicly and that Spain declined to comment.
In December 2024, Kaspersky attributed the newly uncovered intrusions to Careto with medium to high confidence. The linkage was based on highly similar filenames and overlapping tactics, techniques, and procedures with the historic group.
Kaspersky announced in May 2024 that it had detected Careto malware again. The renewed activity included targeting an unnamed organization in Latin America and a second unnamed organization in Central Africa.
In January 2024, Kaspersky observed the FakeHMP implant on an unidentified individual or organization's machine. In this case, attackers used a malicious goopdate.dll placed in the Google Update directory for sideloading instead of the 2022 deployment method.
During the 2022 intrusion, operators deployed a malicious ninput.dll to record microphone audio while hiding Windows microphone-use indicators, then uploaded MP3 recordings to Dropbox. They also used a file stealer targeting browser data, messenger artifacts, and confidential organizational documents.
In 2022, attackers successfully breached the same Latin American organization, compromising its MDaemon email server for persistence. They later moved laterally and deployed the FakeHMP implant by abusing the legitimate HitmanPro Alert driver to load a malicious DLL.
Kaspersky identified a 2019 infection cluster affecting an organization in Latin America and linked it to The Mask. The intrusion used the Careto2 and Goreto frameworks with modular plugins, COM hijacking persistence, and Google Drive-based command-and-control and exfiltration.
After Kaspersky published its 2014 research, Careto operators shut down exposed operations and wiped logs. Researchers viewed the rapid teardown as unusual and consistent with a highly capable government-linked actor.
In 2014, Kaspersky revealed the Careto hacking group and described it as one of the most advanced threats of its time. The disclosure documented victims in 31 countries and broad surveillance capabilities across multiple platforms.
Kaspersky found evidence that Careto, also known as The Mask, had been operating since at least 2007. The group historically targeted governments, diplomatic entities, energy companies, research institutions, and other espionage targets.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.