Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics
The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations. This group's activity has been confirmed through recent investigations, showing a significant evolution…
The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations. This group's activity has been confirmed through recent investigations, showing a significant evolution in their methods to infiltrate critical infrastructure and maintain persistent access to sensitive networks.
Active since at least 2007, Careto has targeted government agencies, diplomatic entities, and research institutions. Known for utilizing zero-day exploits, the group was inactive after early 2014. Recent evidence, however, indicates a resurgence, particularly with attacks in Latin America during 2022.
The group has shifted its focus toward email infrastructure, targeting the MDaemon email server within compromised networks. Instead of deploying obvious malware, Careto used a persistence technique involving MDaemon’s WorldClient webmail component, which supports custom extensions.
The attackers compiled a malicious extension and altered the WorldClient.ini configuration file to redirect HTTP requests to their custom code. This was achieved by configuring the CgiBase6 parameter to "/WorldClient/mailbox" and setting CgiFile6 to a malicious DLL, enabling interaction through standard webmail traffic.
The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations.
Careto deployed the FakeHMP implant across networks using a sophisticated lateral movement strategy. They utilized legitimate system drivers, such as the HitmanPro Alert driver (hmpalert.sys), to inject malicious code into privileged Windows processes like winlogon.exe and dwm.exe.
This implant provided extensive surveillance capabilities, including keystroke logging, screenshot capture, file retrieval, and additional payload deployment. The group's methods exploit legitimate software components, enhancing stealth and persistence in their operations.
This resurgence highlights Careto's continued threat, combining extensive operational experience with innovative infection methods.
Based on reporting by Cyber Security News.
