Home/Threat Actor/Careto / The Mask
Threat Actor

Careto / The Mask

careto_the_mask · spain · active since 2007

Careto / The Mask (canonical Kaspersky GReAT naming derived from "Careto" Spanish slang term for "mask" or "ugly face" included in some malware modules.

SGH secondary backdoor naming) is a Spain state-aligned cyber-espionage cluster active publicly since at least 2007 with Spanish government attribution per the May 23, 2025 TechCrunch disclosure based on multiple former Kaspersky investigators ("There was no doubt of that, at least no reasonable doubt"); Kaspersky has consistently declined formal attribution but February 2014 canonical disclosure identified Spanish- language-speaking developer team rarely-observed in APT attacks.

one of the rare publicly-tracked Spanish- language-speaking clusters in cybersecurity industry analysis, operationally distinct from existing Western- state-aligned clusters in the corpus (Equation Group NSA- attributed + Project Sauron / Strider unattributed Western- suspected + Animal Farm French DGSE-attributed)

Kaspersky GReAT canonical disclosure published at Security Analyst Summit 2014 Punta Cana Dominican Republic on February 10, 2014 documented ~380 victims in 31 countries with primary targeting categories government institutions + diplomatic offices + embassies + energy/oil/gas companies + research organizations + activists + private equity firms; Spanish-cultural-context target selection including heavy Cuba targeting (former Spanish colony), heavy Morocco targeting (Spanish-Moroccan diplomatic + Ceuta/ Melilla territorial context), Spain itself, Gibraltar (Spanish-UK territorial dispute British Overseas Territory), Brazil (Portuguese-speaking former Iberian colony), plus US + UK + France + Germany + China among 31 countries total; signature operational tradecraft includes cross-platform implant sophistication (Windows 32/64-bit + Mac OS X + Linux + possibly Android + iOS) rootkit + bootkit persistence (above Duqu in sophistication per Kaspersky), highly-modular plugin-based Careto architecture + SGH secondary backdoor, 0day exploit access, TecSystem Bulgaria valid code-signing certificate abuse, fake news website lure tradecraft (mimicking The Guardian + Time + Washington Post + Spanish dailies with OS-and-software-specific exploit selection and post-infection redirect to legitimate content), Kaspersky product targeting tradecraft via 5-year- old vulnerability exploit attempts.

January 2014 operational C2 shutdown in response to research-community attention.

10-year operational hiatus 2014-2024.

Kaspersky October 2024 Virus Bulletin "Careto is Back" return disclosure confirmed operational resumption with continued sophisticated implants delivered through 0day exploits; fills historical Tier-4 Spain-state-aligned Western-state- aligned APT cell in the curated corpus.

spain confidence: high 11 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited2

Profile

Careto / The Mask (canonical Kaspersky GReAT naming derived from "Careto" Spanish slang term for "mask" or "ugly face" included in some malware modules.

alternative naming "The Mask" / "SGH" for the secondary more-complex backdoor component) is a Spain state-aligned cyber- espionage cluster active publicly since at least 2007 with attribution to the Spanish government per the May 23, 2025 TechCrunch disclosure based on multiple former Kaspersky investigators who concluded "Careto was a hacking team working for the Spanish government" with "no reasonable doubt." Kaspersky has consistently declined to issue formal public attribution but its February 2014 canonical disclosure identified Spanish-language-speaking developer team, "the authors appear to be native in the Spanish language. This has been observed very rarely in APT attacks." The cluster operates as one of the rare publicly-tracked Spanish-language-speaking clusters in cybersecurity industry analysis. Operationally distinct from existing curated Western-state-aligned clusters in the corpus (Equation Group NSA-attributed, Project Sauron / Strider unattributed Western-suspected, Animal Farm French DGSE-attributed) through (a) Spanish-language-speaking developer attribution; (b) Spanish-cultural-context target selection (Cuba former Spanish colony, Morocco diplomatic relationship + Ceuta/ Melilla, Spain itself, Gibraltar Spanish-UK territorial dispute, Brazil Portuguese-speaking former Iberian colony); (c) signature multi-platform cross-OS sophistication. Operational phases: (1) OPERATIONAL EMERGENCE (2007). Earliest documented Careto sample compilation timestamps from 2007. Variants developed across 2007-2012 era. (2) MODULAR DEVELOPMENT ERA (2012). Most Careto modules created in 2012. Signature highly-modular plugin-based architecture established. (3) KASPERSKY INITIAL DETECTION VIA PRODUCT EXPLOIT ATTEMPTS (2013). Operationally distinctive initial- detection pathway, Kaspersky researchers observed attempts to exploit a 5-year-old Kaspersky product vulnerability. (4) C2 SHUTDOWN + KASPERSKY CANONICAL DISCLOSURE (January- February 2014). January 2014: Careto C2 servers operationally shut down. February 10, 2014: Kaspersky GReAT canonical disclosure at Security Analyst Summit Punta Cana documented ~380 victims in 31 countries. (5) 10-YEAR HIATUS (2014-2024). No publicly-disclosed operational activity for approximately 10 years. (6) KASPERSKY RETURN DISCLOSURE (October 2024). Virus Bulletin 2024 International Conference disclosure confirmed cluster operational resumption. (7) TECHCRUNCH SPAIN ATTRIBUTION DISCLOSURE (May 23, 2025). Canonical Spanish-government attribution per former Kaspersky investigators.

Signature operational tradecraft
  • Spanish-language-speaking developer team: signature Spanish-language strings throughout malware including the "Careto" Spanish slang term that is the cluster's namesake. "Native in the Spanish language" per Kaspersky.
  • Cross-platform implant sophistication: Windows 32/64- bit + Mac OS X + Linux + possibly Android + iOS variants. Operationally rare in publicly-tracked clusters of the 2007-2014 era.
  • Rootkit + bootkit persistence: signature persistence tradecraft above Duqu in operational sophistication per Kaspersky.
  • Highly-modular plugin-based architecture: Careto is "a highly modular system; it supports plugins and configuration files which allow it to perform a large number of functions.".
  • SGH secondary backdoor: more-complex secondary backdoor program complementing primary Careto modular platform.
  • 0day exploit access: signature state-aligned operational resource indicator. Often delivered through zero-day exploits per Kaspersky 2024 disclosure.
  • TecSystem Bulgaria valid certificate abuse: signature code-signing certificate from Bulgarian company TecSystem Ltd. used to bypass Windows security warnings and antivirus heuristic detection.
  • Fake news website lure tradecraft: spear-phishing emails with malicious links to bogus news websites mimicking The Guardian, Time, The Washington Post, plus Spanish dailies. OS-and-software-specific exploit selection with redirect to legitimate news content after infection.
  • Kaspersky product targeting tradecraft: signature operational pattern of attempting to exploit Kaspersky product vulnerabilities for antivirus-bypass tradecraft.
  • Spanish-cultural-context target selection: Cuba former Spanish colony, Morocco diplomatic relationship and Ceuta/ Melilla territorial context, Spain itself (counter- intelligence), Gibraltar Spanish-UK territorial dispute, Brazil former Iberian Portuguese-speaking colony.
  • High-profile target focus: governments, diplomatic offices, embassies, energy + oil + gas companies, research organizations, activists, private equity firms.
  • C2 shutdown operational-security response: pre-emptive C2 shutdown in response to research-community attention (January 2014).
  • 10-year operational hiatus: signature long-duration operational-cessation tradecraft following cluster burn. The cluster fills the historical Tier-4 Spain-state-aligned Western-state-aligned APT cell in this curated corpus, operationally one of the rare publicly-tracked Spanish- language-speaking clusters alongside the broader Western- state-aligned cluster ecosystem (Equation Group NSA- attributed + Project Sauron / Strider unattributed Western-suspected + Animal Farm French DGSE-attributed + Careto / The Mask Spain-attributed = 4 distinct Western- state-aligned clusters in the curated corpus).

Aliases

11
caretothe maskthemaskcareto_the_maskmask aptcareto aptsghsgh backdoorcareto malwaremask malwarethemask apt

Notable Campaigns

11
2025TechCrunch May 2025 Spain Government Attribution Disclosure
2024Kaspersky 'Careto is Back' Return Disclosure (Virus Bulletin 2024 + October 2024)
2014-202410-Year Hiatus Operations Era (2014-2024)
2014Kaspersky GReAT Canonical Careto / The Mask Disclosure (February 10, 2014, Punta Cana)
2014Command-and-Control Servers Operational Shutdown (January 2014)
2013Kaspersky Initial Detection Via Product Vulnerability Exploit Attempts (2013)
2012Careto Modular Development Era (2012)
2007-2014Cross-Platform Implant Tradecraft (Signature Operational Pattern)
2007-2014TecSystem Bulgaria Valid Code-Signing Certificate Abuse (Signature)
2007-2014Fake News Website Lure Tradecraft (Signature)
2007Careto Operational Emergence (Active Since at Least 2007)

Attribution & Reporting

Attributed by
Kaspersky GReATCostin Raiu (Kaspersky GReAT Director)TechCrunch (May 23, 2025 disclosure)Former Kaspersky employees with knowledge of the investigation (per TechCrunch)Bruce Schneier (speculation on Spain attribution)MandiantMicrosoft Threat Intelligence CenterCrowdStrikeSymantec / Broadcom Threat Hunter TeamESETTrend MicroSOPHOS X-OpsSentinelOne / SentinelLabsDark ReadingThreatpost
Key reporting
reportKaspersky GReAT (Costin Raiu, presented at Kaspersky Security Analyst Summit 2014 Punta Cana Dominican Republic): Unveiling The Mask, Careto APT (February 10, 2014), canonical Careto / The Mask comprehensive disclosure
reportKaspersky GReAT: The Careto/Mask APT, Frequently Asked Questions (Securelist, February 2014)
reportKaspersky GReAT: Careto APT's Recent Attacks Discovered (Securelist, October 2024), canonical 10-year-hiatus-end disclosure at Virus Bulletin 2024 International Conference
reportTechCrunch (Lorenzo Franceschi-Bicchierai): Mysterious Hacking Group Careto Was Run by the Spanish Government, Sources Say (May 23, 2025), canonical Spain government attribution disclosure based on former Kaspersky investigators
reportSymantec: The Mask / Careto Large-Scale Global Cyberespionage Campaign Analysis
reportDark Reading: 'The Mask' Espionage Group Resurfaces After 10-Year Hiatus (May 2024)
reportESET / WeLiveSecurity: The Mask aka Careto Initial Disclosure (February 11, 2014)
reportBruce Schneier: The Mask Advanced State-Sponsored Attack Speculation (February 2014 blog post)
reportMandiant: Spain-Aligned Cluster Tracking
reportMicrosoft Threat Intelligence: Western-Aligned Cluster Tracking
reportCrowdStrike Global Threat Report: Spain / Western-Aligned Historical Cluster Tracking
reportTrend Micro: Careto / The Mask Adjacent Cluster Tracking
reportSOPHOS X-Ops: Spanish-Speaking-Cluster Tracking
reportSentinelLabs: Careto / The Mask Operational Analysis
reportMITRE ATT&CK Group G0042, Careto / The Mask
reportMalpedia Actor Profile: The Mask

Operational

State sponsor

Spain state-aligned cluster, Spanish government attribution operationally established via two evidence streams: (a) Kaspersky GReAT canonical February 2014 disclosure identified Spanish-language-speaking developer team but declined to formally attribute to specific state actor.

(b) TechCrunch May 23, 2025 disclosure: per multiple former Kaspersky employees with knowledge of the investigation, Kaspersky internally concluded "Careto was a hacking team working for the Spanish government", per one former employee: "There was no doubt of that, at least no reasonable [doubt]." The Spanish government attribution is operationally supported by multiple convergent evidence streams: (a) Spanish-language-speaking developer team: per Kaspersky GReAT canonical February 2014 disclosure: "the authors appear to be native in the Spanish language. This has been observed very rarely in APT attacks." Spanish- language strings throughout malware modules including the "Careto" Spanish slang term itself (meaning "mask" or "ugly face"). (b) Target selection consistent with Spanish strategic intelligence priorities: per TechCrunch May 2025 disclosure: "Cuba [former Spanish colony], other Careto targets also pointed to Spain. The espionage operation affected hundreds of victims in Brazil, Morocco, Spain itself and, perhaps tellingly, Gibraltar, the disputed British enclave on the Iberian peninsula that Spain has long claimed as its own territory." The Gibraltar targeting is operationally distinctive, Gibraltar is a British Overseas Territory long claimed by Spain, and the operational targeting of Gibraltar from a Spanish-speaking cluster is operationally consistent with Spanish state- aligned strategic intelligence interests in that territorial dispute. (c) Heavy Cuba targeting operational pattern: Cuba is a former Spanish colony with significant ongoing diplomatic and economic ties to Spain. The heavy Cuba targeting is operationally consistent with Spanish state-aligned strategic intelligence interests in the Cuban government. (d) Heavy Morocco targeting operational pattern: Morocco has significant ongoing diplomatic and strategic ties to Spain (including the Spanish enclaves of Ceuta and Melilla in North Africa). The heavy Morocco targeting is operationally consistent with Spanish state-aligned strategic intelligence interests in Morocco and the Spanish-Moroccan diplomatic relationship. (e) Cross-platform extreme sophistication: signature operational sophistication tier including rootkit, bootkit, Mac OS X and Linux versions, and possibly Android and iOS (iPad/iPhone) versions, operationally requiring substantial state-aligned development resources. Per Kaspersky: "Considered by experts as one of the most advanced threats at the moment... above Duqu in terms of sophistication." (f) 0day exploit access: per Kaspersky, "Careto's malware was used to hack into government institutions and private companies around the world." The cluster's use of 0day exploits is operationally consistent with state-aligned operational resources. (g) Operational targeting of Kaspersky products: Kaspersky researchers initially became aware of Careto when "they observed attempts to exploit a vulnerability in the company's products which was fixed five years ago. The exploit provided the malware the capability to avoid detection." The operational targeting of Kaspersky products operationally suggests state-aligned operator confidence in avoiding detection through specific antivirus-bypass tradecraft. Per TechCrunch May 2025: "Kaspersky declined to answer questions about its researchers' conclusions. 'We don't engage in any formal attribution,' Kaspersky spokesperson Mai Al Akkad told TechCrunch in an email. The Spanish Ministry of Defense declined to comment." The cluster operates as one of the rare publicly-tracked Spanish- language-speaking clusters in cybersecurity industry analysis. Operationally distinct cluster from Equation Group (NSA-attributed), Project Sauron / Strider (unattributed Western-suspected), and Animal Farm (French DGSE-attributed) within the broader Western-state-aligned cluster cell.

Motivations
spain_state_aligned_intelligence_collection, cuban_government_intelligence_collection, moroccan_government_intelligence_collection, gibraltar_intelligence_collection, brazilian_intelligence_collection, spanish_domestic_counter_intelligence, latin_american_intelligence_collection, signals_intelligence_via_sophisticated_implants, cross_platform_intelligence_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)25/60 · 41%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SGHSGH BACKDOOR

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin