logo

Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics

ID: fae2dbe9-4113-5f31-b966-7294eb1de3b4

STIX ID: report--fae2dbe9-4113-5f31-b966-7294eb1de3b4

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-01-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Careto ("The Mask") has resurfaced after a decade, executing sophisticated targeted attacks against high-profile organizations and critical infrastructure; researchers observed the group exploiting MDaemon's WorldClient by loading a malicious extension via WorldClient.ini to persist, then deploying a previously unknown FakeHMP implant that abused the HitmanPro Alert driver (hmpalert.sys) to inject into winlogon.exe and dwm.exe for keystroke logging, screenshots, file theft, lateral movement and sustained access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.