A little-known cyber espionage group , The Mask, has been linked to a new series of attacks targeting an anonymous organization in Latin America twice in 2019 and 2022.
See also: New malware technique exploits Windows UIA

Also known as Careto, the group was previously documented by Kaspersky a decade ago, in February 2014, as having targeted over 380 unique victims since 2007. The origins of the hacking group are currently unknown.
Initial access to target networks is facilitated through spear-phishing emails that embed links to malicious websites designed to trigger browser-based zero-day exploits to infect the visitor (e.g., CVE-2012-0773), after which they are redirected to benign websites such as YouTube or a news portal.
There are also some indications that threat actors have developed a comprehensive malware arsenal capable of targeting Windows, macOS, Android, and iOS.
Kaspersky said it spotted The Mask targeting a Latin American organization in 2022, using a yet-unspecified method to gain a foothold and maintain its persistence using an MDaemon email component called WorldClient .
See also: ZLoader malware uses DNS Tunneling technique
The threat actor is said to have compiled its own extension and configured it by adding malicious entries to the WorldClient.ini specifying the path to the extension DLL.

The rogue extension is designed to execute commands that allow for identification, file system interactions, and the execution of additional payloads. In the 2022 attack, the group used this method to spread to other computers within the organization’s network and launch an implant named FakeHMP (“hmpalert.dll”).
The backdoor supports a wide range of functions to access files, record keystrokes, and deploy further malware on the compromised host. Some of the other tools delivered to the compromised systems included a microphone recorder and a file-stealing device.
The cybersecurity firm's investigation further found that the same organization had been subject to a previous attack in 2019 by The Mask, which involved the use of two malware frameworks codenamed Careto2 and Goreto.
See also: New Meeten malware targets macOS and Windows users
Multi-Platform Malware is one of the biggest challenges in cybersecurity. This type of malware is designed to attack different operating systems, such as Windows, macOS, and Linux, thus increasing the likelihood of successful infection. Multi-platform malware often exploits vulnerabilities that are common across multiple systems or uses cross-platform frameworks, making it particularly dangerous. Detecting and combating it requires advanced tools and strategies, as well as constant updates on the latest threats.
Source: thehackernews
