HomeSecurityVirus discovered with global digital espionage activities since 2007

Virus discovered with global digital espionage activities since 2007

The_Mask-s

Kaspersky Lab experts have discovered The Mask virus (also known as Careto), an advanced, Spanish-language threat that has been involved in global digital espionage activities since at least 2007 .

What makes this threat unique is the complexity of the tools used by the attackers. These include highly sophisticated malware, a rootkit and a bootkit, as well as versions for Mac OS X and Linux , and – possibly – versions for Android and iOS (iPad/iPhone).

The Mask/Careto's main targets are government agencies , diplomatic offices and embassies , energy , oil and gas companies , research organizations and activists .

Victims of this targeted attack have been found in 31 countries around the world – from the Middle East and Europe to Africa and the Americas.

The attackers' main goal is to gather sensitive data from the "infected" systems. This includes documents, but also various encryption keys, VPN settings, SSH keys (as a means of identifying a user on an SSH server), as well as RDP files (files used by the Remote Desktop Client to automatically open a connection).

Kaspersky Lab researchers first became aware of this threat last year, when they observed attempts to exploit a vulnerability in the company's products that had been patched five years earlier.

The exploit gave the malware the ability to evade detection. Naturally, this situation piqued the company's interest and so the investigation began.

For its victims, the Careto virus can have devastating results. It monitors all communication channels and collects the most vital information from the victim's machine.

Its detection is extremely difficult , due to its high stealth rootkit capabilities, its built-in functions, and additional digital espionage modules .

Key Findings:

  • It appears that Spanish is the native language of those who developed the threat, something that has been observed very rarely in similar attacks.
  • The campaign had been active for at least five years until January 2014 (some samples of Careto appear to have been deployed since 2007). During Kaspersky Lab's investigations, the command-and-control servers had been shut down.
  • Over 380 victims have been identified across more than 1,000 IP addresses. The victims have been identified in 31 countries including the US, Argentina, Brazil, China, France, Germany, Iran, Iraq, Egypt, Norway, Pakistan, Spain, Switzerland, Turkey and the UK.
  • The complexity and global footprint of the tools used by the attackers makes this digital espionage operation very special, and there was also a customized attack against Kaspersky Lab products.
  • Among other tools, at least one Adobe Flash Player exploit (CVE-2012-0773) was used. This exploit was designed for Flash Player versions prior to versions 10.3 and 11.2.

According to Kaspersky Lab's analysis, The Mask campaign relies on aggressive phishing emails, with links leading to a malicious website. The malicious website contains a series of exploits designed to "infect" the visitor, depending on their system settings.

After successful "infection", the malicious website redirects the user to the safe address mentioned in the e-mail, which may be a YouTube video or an information portal.

For more information you can read the full report.

The_Mask

Source: e-pcmag.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS