Careto, The Mask

Description

(Kaspersky) The Mask is an advanced threat actor that has been involved in cyber-espionage operations since at least 2007. The name “Mask” comes from the Spanish slang word “Careto” (“Ugly Face” or “Mask”) which the authors included in some of the malware modules.

More than 380 unique victims in 31 countries have been observed to date. What makes “The Mask” special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated malware, a rootkit, a bootkit, 32-and 64-bit Windows versions, Mac OS X and Linux versions and possibly versions for Android and iPad/iPhone (Apple iOS).

Names

NameName-Giver
CaretoKaspersky
The MaskKaspersky
MaskKaspersky
Ugly FaceKaspersky

Country

State-sponsored

Motivation

  • Information theft and espionage

First Seen

2007

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Other Information

Uuid

3d291611-962c-42b8-88e8-3db17f464f9b

Last Card Change

2025-06-27