Careto — APT Profile
Careto (The Mask) is a cyber-espionage actor disclosed by Kaspersky in February 2014, with 380+ victim IDs across 31 countries. Kaspersky dates it to at least 2007, a lower bound drawn from sample compile timestamps the vendor itself flags as not fully reliable. Its toolset spanned user-mode and kernel-mode backdoors with rootkit components on Windows, macOS and Linux; Android and iOS builds were suspected but never recovered. All known command-and-control servers went offline in January 2014, and Kaspersky reported a resurgence in December 2024, tying 2019, 2022 and early-2024 intrusions using Careto2, Goreto and FakeHMP to the actor. Operators are assessed as Spanish-speaking, and a May 2025 press report citing anonymous former Kaspersky staff linked the group to the Spanish government, but no government or vendor has formally attributed it.Also tracked as
The Mask, Ugly Face
Tools & malware
- Careto Backdoor
- Careto2 Modular backdoor framework
- FakeHMP Implant
- Goreto Backdoor
- sbd Backdoor
- SGH Modular kernel-mode backdoor
Vendor research
- Unveiling "Careto" - The Masked APT Kaspersky
- The Careto/Mask APT: Frequently Asked Questions Kaspersky (Securelist)
- Careto is back: what's new after 10 years of silence? Kaspersky (Securelist)
- The Mask has been unmasked again Kaspersky (Virus Bulletin)