Careto Hacker Group Resurfaces After a Decade, Unleashing New Attack Techniques
The Careto Advanced Persistent Threat (APT), commonly referred to as "The Mask," has re-emerged after a decade, showcasing advanced attack techniques that highlight the group’s ongoing evolution and technical capabilities.
The Careto Advanced Persistent Threat (APT), commonly referred to as "The Mask," has re-emerged after a decade, showcasing advanced attack techniques that highlight the group’s ongoing evolution and technical capabilities.
Research conducted by Kaspersky was presented at the 34th Virus Bulletin International Conference in October, marking the first significant detection of Careto activity since early 2014.
Active since at least 2007, The Mask APT has been involved in complex cyberattacks, targeting high-profile entities such as governments, diplomatic organizations, and research institutions.
The group employs elaborate implants often deployed through zero-day exploits, positioning them among the most formidable threat actors in cybersecurity.
Recent investigations by Kaspersky revealed two significant attack clusters, including a 2022 incident involving a Latin American organization. During this attack, threat actors compromised an MDaemon email server using a novel persistence method via the WorldClient webmail component.
The attackers exploited WorldClient’s extension-loading feature, which allows custom HTTP request handling via the WorldClient.ini configuration file. By creating a malicious extension and modifying the CgiBase6 and CgiFile6 parameters, they maintained persistent access through HTTP requests, enabling reconnaissance, file system manipulation, and payload execution.
The group employs elaborate implants often deployed through zero-day exploits, positioning them among the most formidable threat actors in cybersecurity.
The group demonstrated advanced lateral movement by exploiting a legitimate HitmanPro Alert driver (hmpalert.sys). They uploaded four files to compromised systems: the legitimate driver, a malicious DLL payload, a .bat file, and an XML file with scheduled task descriptions.
This method involved injecting a payload, known as "FakeHMP," into privileged processes like winlogon.exe and dwm.exe during system startup. The FakeHMP implant offered capabilities including file retrieval, keystroke logging, screenshot capture, and payload deployment.
The use of COM hijacking for persistence, alongside a virtual file system for plugin storage, allowed for capabilities such as configuration management, file monitoring, and data exfiltration to OneDrive storage.
In early 2024, an alternate delivery technique utilizing Google Updater was observed, indicating the group's continued tactical evolution. The same organization was compromised in 2019 using frameworks "Careto2" and "Goreto," with Goreto, coded in Golang, utilizing Google Drive for command retrieval and supporting operations like file transfer, shell command execution, keylogging, and screenshot capture.
Kaspersky attributed these attacks to The Mask with medium-to-high confidence based on various indicators. File naming conventions were consistent with those used by The Mask between 2007-2013, featuring patterns such as "~df01ac74d8be15ee01.tmp" and "c_27803.nls." Plugin names like "FileFilter," "Storage," and "ConfigMgr" matched historical naming patterns.
Shared tactics, techniques, and procedures (TTPs), including virtual file systems for plugin storage, COM hijacking for persistence, and cloud storage for data exfiltration, further support this attribution.
The resurgence of The Mask highlights that sophisticated threat actors can remain dormant for extended periods while sustaining their technical capabilities, posing a significant threat to high-value targets globally.
Based on reporting by GBHackers.
