Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics

The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations. This group's activity has been confirmed through recent investigations, showing a significant evolution…

The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations. This group's activity has been confirmed through recent investigations, showing a significant evolution in their methods to infiltrate critical infrastructure and maintain persistent access to sensitive networks.

Active since at least 2007, Careto has targeted government agencies, diplomatic entities, and research institutions. Known for utilizing zero-day exploits, the group was inactive after early 2014. Recent evidence, however, indicates a resurgence, particularly with attacks in Latin America during 2022.

The group has shifted its focus toward email infrastructure, targeting the MDaemon email server within compromised networks. Instead of deploying obvious malware, Careto used a persistence technique involving MDaemon’s WorldClient webmail component, which supports custom extensions.

The attackers compiled a malicious extension and altered the WorldClient.ini configuration file to redirect HTTP requests to their custom code. This was achieved by configuring the CgiBase6 parameter to "/WorldClient/mailbox" and setting CgiFile6 to a malicious DLL, enabling interaction through standard webmail traffic.

The Careto threat group, also known as "The Mask," has re-emerged after a decade, employing advanced attack techniques on high-profile organizations.
Michael Reeves · Thehackingpost

Careto deployed the FakeHMP implant across networks using a sophisticated lateral movement strategy. They utilized legitimate system drivers, such as the HitmanPro Alert driver (hmpalert.sys), to inject malicious code into privileged Windows processes like winlogon.exe and dwm.exe.

This implant provided extensive surveillance capabilities, including keystroke logging, screenshot capture, file retrieval, and additional payload deployment. The group's methods exploit legitimate software components, enhancing stealth and persistence in their operations.

Advertisement

This resurgence highlights Careto's continued threat, combining extensive operational experience with innovative infection methods.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories