Careto is back: what’s new after 10 years of silence?
ID: a0880fcf-2734-5d80-ac91-64c4718868f0
STIX ID: report--a0880fcf-2734-5d80-ac91-64c4718868f0
Feed Name: Securelist by Kaspersky
Threat Score
Kaspersky researchers disclosed renewed activity by The Mask (Careto) APT observed across 2019–2024: targeted intrusions against high-profile organizations deploying custom implants (FakeHMP, Careto2, Goreto), novel persistence via MDaemon WorldClient extensions and abuse of the HitmanPro Alert driver, lateral movement using scheduled tasks and driver-based DLL injection, cloud-based exfiltration, and multiple attribution links to historical Careto operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
