Attribute | Details |
---|---|
Threat Actors | The Mask (aka Careto) – Active since at least 2007, performing sophisticated attacks against high-profile organizations, including governments, diplomatic entities, and research institutions. |
Campaign Overview | Newly observed attacks in 2022 and 2024 attributed to The Mask, using advanced implants and infection techniques targeting email servers, cloud storage, and leveraging persistence methods. |
Target Regions | Latin America, with identified attacks against high-profile organizations in 2019, 2022, and 2024. |
Methodology | Persistence via MDaemon email server extensions, lateral movement through malicious drivers and DLL injection, COM hijacking, leveraging cloud storage for data exfiltration, and TTP overlaps with historic campaigns. |
Product Targeted | MDaemon email servers, HitmanPro Alert drivers, system processes like winlogon.exe and dwm.exe , and cloud services like Google Drive and OneDrive. |
Malware Reference | FakeHMP implant, Careto2 framework, Goreto toolset, Careto implants. |
Tools Used | WorldClient component extensions, HitmanPro Alert software driver (hmpalert.sys ), malicious DLL (hmpalert.dll ), Google Updater abuse, COM hijacking. |
Vulnerabilities Exploited | Persistence exploits in MDaemon’s WorldClient extensions and file-based COM hijacking. |
TTPs | Cloud-based command and control, lateral movement via scheduled tasks, malicious drivers, keystroke logging, screenshot capturing, data exfiltration, COM hijacking, plugin-based modular frameworks. |
Attribution | Attributed to The Mask (Careto) with medium to high confidence, based on TTP overlaps, reused file names, and unique methods linked to historical campaigns by this actor. |
Recommendations | Regular patching and hardening of email servers, monitoring cloud storage for anomalous activity, securing COM objects, endpoint monitoring for malware, and advanced threat intelligence sharing. |
Source | Securelist by Kaspersky |
Read full article:https://securelist.com/careto-is-back/114942/
The above summary has been generated by an AI language model
Leave a Reply