logo

'The Mask' Espionage Group Resurfaces After 10-Year Hiatus

ID: 00651c22-04bc-5d5c-a8ea-f8eb132f46d5

STIX ID: report--00651c22-04bc-5d5c-a8ea-f8eb132f46d5

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-05-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky reports that the long-dormant Careto APT (The Mask) has re-emerged, targeting at least two organizations in Central Africa and Latin America using custom multi-modular implants (FakeHMP, Careto2, Goreto, MDaemon implant). The attackers gained access via MDaemon email servers, leveraged a previously unknown vulnerability in a security product to distribute implants, maintained persistence (including abuse of a HitmanPro Alert driver), and exfiltrated browser credentials, messenger cookies, documents, and recordings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.