Careto — APT Profile

Careto (The Mask) is a cyber-espionage actor disclosed by Kaspersky in February 2014, with 380+ victim IDs across 31 countries. Kaspersky dates it to at least 2007, a lower bound drawn from sample compile timestamps the vendor itself flags as not fully reliable. Its toolset spanned user-mode and kernel-mode backdoors with rootkit components on Windows, macOS and Linux; Android and iOS builds were suspected but never recovered. All known command-and-control servers went offline in January 2014, and Kaspersky reported a resurgence in December 2024, tying 2019, 2022 and early-2024 intrusions using Careto2, Goreto and FakeHMP to the actor. Operators are assessed as Spanish-speaking, and a May 2025 press report citing anonymous former Kaspersky staff linked the group to the Spanish government, but no government or vendor has formally attributed it.

Also tracked as

The Mask, Ugly Face

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions