HomeinetThe threatening "Mask" points to a government finger, according to Kaspersky Lab

The threatening "Mask" points to a government finger, according to Kaspersky Lab

One of the four largest security solutions companies in the world announced that it has identified the traces and methods of one of the most advanced global digital espionage operations.
caretaker
According to Kaspersky Lab, the targets of “The Mask” included government agencies, energy, oil and gas companies, and activists. The evidence Kaspersky identified leads its experts to believe that this is a government-sponsored campaign, with its perpetrators appearing to be Spanish-speaking. The virus is called “The Mask” and is known and “Careto” and is believed to be created by Spanish speakers. The virus has been circulating since at least 2007, experts say Kaspersky and the complexity of the tools used make this threat unique: a highly sophisticated malware, one rootkit and one bootkit, as well as versions for Mac OS X and Linux and – possibly – versions for Android and iOS (iPad/iPhone). Its main goals The Mask/ Careto These include government agencies, diplomatic missions and embassies, energy, oil and gas companies, research organizations and activists. Victims of this targeted attack have been found in 31 countries around the world – from the Middle East and Europe to Africa and the Americas.

The attackers' main goal is to gather sensitive data from the "infected" systems. This includes documents, but also various encryption keys, VPN settings, SSH keys (as a means of identifying a user on an SSH server), as well as RDP files (files used by the Remote Desktop Client to automatically open a connection).

“There are many reasons to believe that this could be a state-sponsored campaign. First of all, we observed a very high degree of professionalism in the operational processes of the group behind this attack: from infrastructure management, to the disruption of the business, to the way they avoided exposure through access rules, to the fact that they completely disappeared their actions instead of deleting logs. The combination of the above shows that this threat surpasses Duqu in terms of evolution, making it one of the most advanced we have encountered so far,” said Costin Raiu, Director, Global Research and Analysis Team (GReAT) at Kaspersky Lab.

Kaspersky Lab researchers first became aware of this threat in 2013, when they noticed attempts to exploit a vulnerability in their products that had been patched five years earlier. The exploit allowed the malware to evade detection. Naturally, this situation piqued the company’s interest, and so the investigation began.

For its victims, the Careto can have devastating results. It monitors all communication channels and collects the most vital information from the victim's machine. It is extremely difficult to detect, due to its high stealth rootkit capabilities, built-in functions and additional digital espionage modules.

Key Findings:

  • It appears that Spanish is the native language of those who developed the threat, something that has been observed very rarely in similar attacks.
  • The campaign had been active for at least five years until January 2014 (some samples of Careto appear to have been deployed since 2007). During Kaspersky Lab's investigations, the command-and-control servers had been shut down.
  • Over 380 victims have been identified across more than 1000 IP addresses. Affected systems have been identified in: Algeria, Argentina, Belgium, Bolivia, Brazil, China, Colombia, Costa Rica, Cuba, Egypt, France, Germany, Gibraltar, Guatemala, Iran, Iraq, Libya, Malaysia, Mexico, Morocco, Norway, Pakistan, Poland, South Africa, Spain, Switzerland, Tunisia, Turkey, United Kingdom, United States and Venezuela.
  • The sophistication and global footprint of the tools used by the attackers make this cyber espionage operation very special. Among other things, this campaign utilized sophisticated exploits, highly advanced malware, a rootkit, a bootkit, and was developed in versions for Mac OS X and Linux, and – potentially – Android and iOS. The Mask also used a customized attack against Kaspersky Lab products.
  • Among other tools, at least one Adobe Flash Player exploit (CVE-2012-0773) was used. This exploit was designed for Flash Player versions prior to 10.3 and 11.2. It was originally discovered by VUPEN and used in 2012 to escape the Google Chrome sandbox and win the CanSecWest Pwn2Own competition.

According to Kaspersky Lab’s analysis, The Mask campaign relies on aggressive phishing emails, with links leading to a malicious website. The malicious website contains a series of exploits designed to “infect” the visitor, depending on their system settings. After successful “infection”, the malicious website redirects the user to the safe address mentioned in the email, which can be a YouTube video or an information portal.

It should be noted that websites with exploits do not automatically "infect" visitors. Instead, attackers host the exploits in specific folders on the website, which are not directly mentioned anywhere, except in malicious e-mails. Sometimes, attackers use subdomains on the "infected" websites, to make them look more realistic.

  • These subdomains simulate subsections of the main newspapers in Spain, as well as some international ones, such as the “Guardian” and the “Washington Post”.

The malware monitors all communication channels and collects the most critical information from the “infected” system. Its detection is extremely difficult, due to the increased stealth rootkit capabilities it has. Careto is an extremely modular system. It supports plugins and configuration files, which allow it to perform a large number of functions. In addition to the built-in functions, Careto operators can “upload” additional functions that could perform any malicious task.

However, Kaspersky Lab notes that its products detect and eliminate all known versions of The Mask/Careto.

You can read the full report on The Mask/Careto, with details on the malicious tools, statistics, and signs of an attack. Finally, you can see answers to frequently asked questions about “The Mask.”

In.gr Technology

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS