Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Careto Hacker Group Resurfaces After a Decade, Unleashing New Attack Techniques

The Careto Advanced Persistent Threat (APT), commonly referred to as "The Mask," has re-emerged after a decade, showcasing advanced attack techniques that highlight the group’s ongoing evolution and technical capabilities.

The Careto Advanced Persistent Threat (APT), commonly referred to as "The Mask," has re-emerged after a decade, showcasing advanced attack techniques that highlight the group’s ongoing evolution and technical capabilities.

Research conducted by Kaspersky was presented at the 34th Virus Bulletin International Conference in October, marking the first significant detection of Careto activity since early 2014.

Active since at least 2007, The Mask APT has been involved in complex cyberattacks, targeting high-profile entities such as governments, diplomatic organizations, and research institutions.

The group employs elaborate implants often deployed through zero-day exploits, positioning them among the most formidable threat actors in cybersecurity.

Recent investigations by Kaspersky revealed two significant attack clusters, including a 2022 incident involving a Latin American organization. During this attack, threat actors compromised an MDaemon email server using a novel persistence method via the WorldClient webmail component.

The attackers exploited WorldClient’s extension-loading feature, which allows custom HTTP request handling via the WorldClient.ini configuration file. By creating a malicious extension and modifying the CgiBase6 and CgiFile6 parameters, they maintained persistent access through HTTP requests, enabling reconnaissance, file system manipulation, and payload execution.

The group employs elaborate implants often deployed through zero-day exploits, positioning them among the most formidable threat actors in cybersecurity.
Adam Foster · Thehackingpost

The group demonstrated advanced lateral movement by exploiting a legitimate HitmanPro Alert driver (hmpalert.sys). They uploaded four files to compromised systems: the legitimate driver, a malicious DLL payload, a .bat file, and an XML file with scheduled task descriptions.

This method involved injecting a payload, known as "FakeHMP," into privileged processes like winlogon.exe and dwm.exe during system startup. The FakeHMP implant offered capabilities including file retrieval, keystroke logging, screenshot capture, and payload deployment.

The use of COM hijacking for persistence, alongside a virtual file system for plugin storage, allowed for capabilities such as configuration management, file monitoring, and data exfiltration to OneDrive storage.

In early 2024, an alternate delivery technique utilizing Google Updater was observed, indicating the group's continued tactical evolution. The same organization was compromised in 2019 using frameworks "Careto2" and "Goreto," with Goreto, coded in Golang, utilizing Google Drive for command retrieval and supporting operations like file transfer, shell command execution, keylogging, and screenshot capture.

Advertisement

Kaspersky attributed these attacks to The Mask with medium-to-high confidence based on various indicators. File naming conventions were consistent with those used by The Mask between 2007-2013, featuring patterns such as "~df01ac74d8be15ee01.tmp" and "c_27803.nls." Plugin names like "FileFilter," "Storage," and "ConfigMgr" matched historical naming patterns.

Shared tactics, techniques, and procedures (TTPs), including virtual file systems for plugin storage, COM hijacking for persistence, and cloud storage for data exfiltration, further support this attribution.

The resurgence of The Mask highlights that sophisticated threat actors can remain dormant for extended periods while sustaining their technical capabilities, posing a significant threat to high-value targets globally.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories