Kaspersky Lab Outs ‘The Mask’ Cyber-Spy Attacks

EUThe Mask,EU aka Careto, has been outed. Kaspersky Lab has discovered an advanced Spanish-language speaking threat actor that has been involved in global cyber-espionage operations since at least 2007. The Mask comes with a complex toolset, including highly sophisticated malware, a rootkit, bootkit, Mac OS X and Linux versions and possibly versions for Android and Apple iOS.

Kaspersky cited government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists as the primary targets. The firm found victims of the attacks in 31 countries, from the Middle East and Europe to Africa and the Americas.

The attackers' goal is to gather sensitive data from the infected systems, such as office documents, encryption keys, VPN configurations, SSH keys (serving as a means of identifying a user to an SSH server) and RDP files (used by the remote desktop client to automatically open a connection to the reserved computer), the firm said.

A Nation-State Sponsored Campaign?

If KasperskyEUs analysis is correct, an infection can be disastrous for victims. Careto intercepts all communication channels and collects the most vital information from the victimEUs machine. One thing is certain, the firm said, detection can be difficult because of stealth rootkit capabilities, built-in functionalities and additional cyber-espionage modules.

EUSeveral reasons make us believe this could be a nation-state-sponsored campaign. First of all, we observed a very high degree of professionalism in the operational procedures of the group behind this attack,EU said Costin Raiu, director of the Global Research and Analysis Team (GReAT) at Kaspersky Lab.

EUFrom infrastructure management, shutdown of the operation, avoiding curious eyes through access rules and using wiping instead of deletion of log files. These combine to put this APT ahead of Duqu in terms of sophistication, making it one of the most advanced threats at the moment. This level of operational...

Comments are closed.