Careto Hacker Group Returns After a Decade of Silence with New Attack Tactics

After a decade-long absence, the elusive advanced persistent threat (APT) group known as Careto, or The Mask, has resurfaced with a new wave of sophisticated cyberattacks.

First exposed in 2014 by Kaspersky, the group is known for highly targeted operations against government agencies, diplomatic organizations, and research institutions worldwide.

At the 34th Virus Bulletin International Conference, Kaspersky researchers reported that Careto has been active since 2019, with recent campaigns observed as late as 2024.

The new operations leverage unconventional infection and persistence techniques, showing that the actor has evolved its methods while retaining recognizable traces of its earlier toolsets.

Exploiting Email Servers for Persistence

One of the most notable discoveries arose from a 2022 cyberattack against a Latin American organization, in which Careto compromised the company’s MDaemon email server.

The attackers exploited a webmail component called WorldClient, which allows loading custom HTTP extensions via configuration entries in the WorldClient.ini file.

By inserting malicious parameters specifically “CgiBase6” and “CgiFile6,” the attackers deployed their own extension accessible through a crafted URL.

This provided them with persistent remote access to the system and enabled command execution via ordinary web requests.

The malicious extension conducted reconnaissance, performed file-system operations, and deployed a payload.

FakeHMP Implant and Driver Abuse

The same 2022 campaign also involved a sophisticated implant, FakeHMP, embedded in a modified hmpalert.dll library.

To install it, the attackers exploited the legitimate HitmanPro Alert driver (hmpalert.sys), which loads DLLs into system processes without verifying their authenticity.

By replacing the target DLL, Careto injected FakeHMP into privileged Windows processes, such as winlogon.exe and dwm.exe, during startup.

FakeHMP’s capabilities include keylogging, screenshot capture, file theft, and the deployment of additional payloads.

In one 2024 case, attackers used Google Updater rather than scheduled tasks to infect systems, demonstrating their adaptability and technical precision.

Authentication panel of the WorldClient component
Authentication panel of the WorldClient component

securelist investigation linked this new activity to previous Careto intrusions from 2019, which involved two frameworks: Careto2 (C++) and Goreto (Go).

These frameworks were designed for modular plugin management, exfiltration via cloud services such as OneDrive and Google Drive, and persistence via COM hijacking.

Kaspersky’s researchers identified matching filenames, plugin structures, and persistence mechanisms between the old and new campaigns, thereby confirming the same group’s involvement with medium to high confidence.

Careto’s reemergence highlights the APT’s enduring sophistication and creativity. From abusing legitimate email servers to exploiting trusted security software drivers, The Mask continues to evolve, proving that even after ten years of silence, some threat actors never truly fade away.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories