Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Careto (malware)

From Wikipedia, the free encyclopedia
Espionage malware discovered in 2014
Careto
AliasThe Mask
ClassificationSpyware
Isolation date2014
OriginNation state

Careto (Spanish slang for "face"), sometimes calledThe Mask, is a piece of espionagemalware discovered byKaspersky Lab in 2014. Because of its high level of sophistication and professionalism, and a target list that included diplomatic offices and embassies, Careto is believed to be the work of a nation state.[1] Kaspersky believes that the creators of the malware were Spanish-speaking.[1]

Because of the focus on Spanish-speaking victims, the heavy targeting ofMorocco, and the targeting ofGibraltar,Bruce Schneier speculates that Careto is operated bySpain.[2]

Payload

[edit]

Careto normally installs a second and more complex backdoor program called SGH. SGH is easily modifiable and also has a wider arsenal including the ability to intercept system events, file operations, and performing a wider range of surveillance features.[3] The information gathered by SGH and Careto can includeencryption keys,virtual private network configurations, andSSH keys and other communication channels.[4]

Detection and removal

[edit]

Careto is hard to discover and remove because of its use ofstealth capabilities. In addition, most of the samples have beendigitally signed. The signatures are issued from a Bulgarian company, TecSystem Ltd., but the authenticity of the company is unknown. One of the issuedcertificates was valid between June 28, 2011 and June 28, 2013. Another was valid from April 18, 2013 to July 18, 2016, but was revoked byVerisign.[5]

Careto was discovered when it made attempts to circumventKaspersky security products.[6] Upon discovery of Careto trying to exploit their software, Kaspersky started to investigate further. As part of collecting statistics, multiplesinkholes were placed on the command and control servers.[5]

Currently most up-to-dateantivirus software can discover and successfully remove the malware.

Distribution

[edit]

On investigation of the command and control servers, discoveries showed that more than 380 victims were infected. From the information that has been uncovered, the victims were infected with the malware by clicking on aspear phishing link which redirected to websites that had software that Careto could exploit, such asAdobe Flash Player. The player has since been patched and is no longer exploitable by Careto. The websites that contained the exploitable software had names similar to popular newspapers, such asThe Washington Post andThe Independent.[7]

The malware is said to have multiplebackdoors toLinux,Mac OS X, andWindows. Evidence of a possible fourth type of backdoor toAndroid andIOS was discovered on the C&C servers, but no samples were found.[3]

It is estimated that Careto has beencompiled as far back as 2007. It is now known that the attacks ceased in January 2014.[5]

References

[edit]
Look upcareto in Wiktionary, the free dictionary.
  1. ^ab"Kaspersky Lab Uncovers "The Mask": One of the Most Advanced Global Cyber-espionage Operations to Date Due to the Complexity of the Toolset Used by the Attackers, 11 February 2014". Archived fromthe original on 21 February 2014. Retrieved11 February 2014.
  2. ^""The Mask" Espionage Malware - Schneier on Security".schneier.com. 11 February 2014.
  3. ^abLucian Constantin (11 February 2014)."Unveiling 'The Mask': Sophisticated malware ran rampant for 7 years".PCWorld.
  4. ^"Kaspersky Lab Uncovers "The Mask": One of the Most Advanced Global Cyber-espionage Operations to Date Due to the Complexity of the Toolset Used by the Attackers". Archived fromthe original on 2014-02-21. Retrieved2014-02-11.
  5. ^abc"The Careto/Mask APT: Frequently Asked Questions". 10 February 2014.
  6. ^"Securelist". 10 February 2014. Retrieved3 April 2015.
  7. ^"Unveiling 'The Mask': Sophisticated malware ran rampant for 7 years". Pcworld. Retrieved2 April 2015.
Hacking in the 2010s
Major incidents
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
Hacktivism
Groups
Individuals
Majorvulnerabilities
publiclydisclosed
Malware
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
Retrieved from "https://en.wikipedia.org/w/index.php?title=Careto_(malware)&oldid=1321684386"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp