'The Mask' Espionage Group Resurfaces After 10-Year Hiatus
ID: 00651c22-04bc-5d5c-a8ea-f8eb132f46d5
STIX ID: report--00651c22-04bc-5d5c-a8ea-f8eb132f46d5
Feed Name: Dark Reading
Kaspersky reports that the long-dormant Careto APT (The Mask) has re-emerged, targeting at least two organizations in Central Africa and Latin America using custom multi-modular implants (FakeHMP, Careto2, Goreto, MDaemon implant). The attackers gained access via MDaemon email servers, leveraged a previously unknown vulnerability in a security product to distribute implants, maintained persistence (including abuse of a HitmanPro Alert driver), and exfiltrated browser credentials, messenger cookies, documents, and recordings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
