News / Science & Technology

'Mask' Malware Called 'Most Advanced' Cyber-espionage Operation

FILE - A man types on a computer keyboard.
FILE - A man types on a computer keyboard.

Related Articles

Sochi Games Present Hacking Minefield

If you do not need the device, do not take it, US State Department warns

More Questions than Answers About China Internet Outage

Chinese officials point to hackers, while others say it was a glitch in the Great Firewall that caused massive outages
Researchers at the Internet security firm Kaspersky Lab say they have uncovered what they’re calling “one of the most advanced global cyber-espionage operations to date.”

The malware is called “Careto,” which roughly means face or mask in Spanish. Since at least 2007, it has netted 380 unique victims in 31 countries, Kaspersky said.

Kaspersky called the Mask  “an extremely sophisticated piece of malware,” which is very hard to detect.

The malware predominantly targets government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists, Kaspersky said.

Countries where Mask infections have been observed include several in Latin America, including Argentina, Bolivia, Brazil, Colombia, Costa Rica, Cuba, Guatemala, Mexico and Venezuela.

Additional countries included China the United States, Turkey, Egypt, France, Germany, Belgium, Poland, South Africa, Spain, Switzerland, Tunisia and the United Kingdom.

Spanish language tie

Apart from the Mask’s duration and scope, it is of interest because the “authors appear to be native in the Spanish language which has been observed very rarely in APT (advanced persistent threat) attacks,” according to Kaspersky.

According to Christopher Burgess, CEO of Prevendra, Inc., an Internet security firm, “the Spanish-language market has not been a primary focus of the information security community at the enterprise/government or individual consumer level.”

“It is well known the Spanish banking software offerings are among the best, thus the targeting of the ingredients of the various countries’ economic backbones and foreign diplomacy of the region is most interesting,” he said.

Burgess said that the big question is who could pull this off?

Kaspersky offers one idea.

“Several reasons make us believe this could be a nation-state sponsored campaign, said Costin Raiu, Director of the Global Research and Analysis Team at Kaspersky Lab in a statement.

“First of all, we observed a very high degree of professionalism in the operational procedures of the group behind this attack," he said.

"From infrastructure management, shutdown of the operation, avoiding curious eyes through access rules and using wiping instead of deletion of log files," he said.

"These combine to put this APT ahead of Duqu (another malware) in terms of sophistication, making it one of the most advanced threats at the moment," he said. "This level of operational security is not normal for cyber-criminal groups.”

Dmitry Bestuzhev, head of Kaspersky’s research center for Latin America, has his own strong suspicions.

“We can certainly say it’s some Spanish speaking government,” he said in an email. “We say it’s a government because of the Careto complexity. The attackers invested a lot of science time and also money. This can be only a government.”

But Matthew Aid, a an independent intelligence analyst, said he didn’t think it was a nation-state like China, Russia or the U.S.

“It sounds like something a group of hackers would do,” he said.

He said that the programming used in a lot of malware systems that could be done by “some kids sitting at a terminal thinking how they can put malware out into the ether.”

“It’s not all that hard to do,” he said.

Taking off the 'Mask'

Kaspersky said they first became aware of the Mask last year when it tried “to exploit a vulnerability in the company’s products which was fixed five years ago.”

Infections occur through spear-phishing e-mails with links to a “malicious website.”

Spear-phishing emails appear to come from a trusted source. After infecting the computer, the malicious website sends the user to the real website referenced in the email.

Kaspersky said the Mask “can intercept network traffic, keystrokes, Skype conversations, PGP keys, analyse WiFi traffic, fetch information from all Nokia devices, screen captures and monitor all file operations.”

Bestuzhev said the malware stole “secrets of the latest research done in the laboratories, diplomatic documents, government plans and documents in general.”

“It was also stealing private encryption keys and private encryption certificates used to cipher connections and locally stored data,” he said. “Additionally the attackers stole certificated used to signed PDF documents."

"It’s a very important point since now they can build malicious PDF files including exploits and when to sign them with a valid signature, so nobody would suspect it is something malicious which would allow to trespass many security filters,” he said.

Concerns about information

Aid said that he sometimes thinks Kaspersky can be “alarmist,” but that he liked that the company “goes places and looks under rocks” that other security firms don’t.

“They don’t give you the means by which you can make an independent assessment,” he said. “This is the sixth or seventh major storm they’ve raised, and then it disappears, and you sort of wonder has this malware disappeared or is it still out there in the ether?”

Kaspersky said that during the investigation into the Mask, the command and control servers, which were in Latin America, were shut down, meaning, at least temporarily, the malware can’t call home.

But Aid is quick to warn about the longevity of malware.

“When you insert something into the Internet, it never dies,” he said. “Once it’s on the Internet, it will never go away.”

You May Like

Myanmar Fighting Poses Dilemma for China

To gain some insight into conflict, VOA’s Steve Herman spoke with Min Zaw Oo, director of ceasefire negotiation and implementation at Myanmar Peace Center More

Australia Concerned Over Islamic State 'Brides'

Canberra believes there are between 30 and 40 Australian women who have taken part in terror attacks or are supporting the Islamic State terror network More

Recreational Marijuana Use Now Legal in Washington, DC

Law allows adults 21 and over to privately possess and smoke 0.05 kilogram of pot, and to grow small amounts of the plant More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
US Supreme Court Hears Hijab Discrimination Casei
X
Katherine Gypson
February 25, 2015 11:30 PM
The U.S. Supreme Court has heard opening arguments in a workplace religious discrimination case that examines whether a clothing store can refuse to hire a young woman for wearing the headscarf she says is a symbol of her Muslim faith. Katherine Gypson reports from the Supreme Court.
Video

Video US Supreme Court Hears Hijab Discrimination Case

The U.S. Supreme Court has heard opening arguments in a workplace religious discrimination case that examines whether a clothing store can refuse to hire a young woman for wearing the headscarf she says is a symbol of her Muslim faith. Katherine Gypson reports from the Supreme Court.
Video

Video Falling Gas Prices Hurt Nascent Illinois Hydraulic Fracturing Industry

Falling oil prices are helping consumers purchase cheaper petroleum at the pump. But that’s made hydraulic fracturing or “fracking” less economically viable for the companies in the United States invested in the process. VOA’s Kane Farabaugh reports on one Midwestern town that was hoping to change its fortunes by cashing in on the next big U.S. oil boom.
Video

Video Fighting in Sudan's South Kordofan Fuels Mass Displacement

Heavy fighting in Sudan's South Kordofan state is causing hundreds of thousands to flee into uncertain conditions. Local aid organizations estimate as many as 400,000 civilians have been internally displaced since the conflict began more than three years ago, while another 250,000 have fled across the border to refugee camps in South Sudan. VOA's Adam Bailes reports.
Video

Video Lao Dam Project Runs Into Opposition

A Lao dam project on a section of the Mekong River is drawing opposition from local fishermen, international environmental groups and neighboring countries. VOA's Say Mony visited the region to investigate the concerns. Colin Lovett narrates.
Video

Video A Filmmaker Discovers Her Biracial Identity in "Little White Lie

Lacey Schwartz grew up in an upper middle-class Jewish family, in a town in upstate New York where almost everyone she knew was white. She assumed that she was, as well. Her recent documentary, Little White Lie, tells the story of how she uncovered the secret of her true racial background. VOA’s Carolyn Weaver has more on the film.
Video

Video Deep Under Antarctic Ice Sheet, Life!

With the end of summer in the Southern hemisphere, the Antarctic research season is over. Scientists from Northern Illinois University are back in their laboratory after a 3-month expedition on the Ross Ice Shelf, the world’s largest floating ice sheet. As VOA’s Rosanne Skirble reports, they hope to find clues to explain the dynamics of the rapidly melting ice and its impact on sea level rise.
Video

Video US-Cuba Normalization Talks Resume Friday

Negotiations aimed at normalizing diplomatic relations between the U.S. and Cuba resume Friday. On the table: lifting a half-century trade embargo and easing banking and travel restrictions. There's opposition in Congress, but some analysts say there may be sufficient political and economic incentives in both nations for a potential breakthrough this year. VOA's Mil Arcega reports.
Video

Video Pakistan's Deadline For SIM Registration Has Cellphone Users Scrambling

Pakistani cell phone users have until midnight Thursday to register their SIM cards, or their service will be cut off. While some privacy experts worry about government intrusion, many Pakistanis are just worried about keeping their phone lines open. VOA Deewa reporter Arshad Muhmand has more from Peshawar.
Video

Video Myanmar Warns Factory Workers to End Strikes

Outside Myanmar's main city Yangon, thousands of workers walked off their jobs earlier this month demanding a doubling of their wages, pay raises after a year and input from labor unions on industrial regulations. Since Friday, the standoff has grown more tense as police moved in to disrupt the sit-ins, resulting in clashes that injured people from both sides. VOA correspondent Steve Herman visited industrial zones which have become a focus of Myanmar's fledgling workers rights movement.
Video

Video Oscar Winners Do More Than Thank the Academy

The Academy Awards presentation is Hollywood’s night to reward the best movies from the previous year. It’s typically a lot of glitter, a lot of thank you’s, a lot of speeches. But many of this year’s speeches carried messages beyond the thank you's. VOA’s Carolyn Presutti takes a look.

All About America

Circumventing Censorship

An Internet Primer for Healthy Web Habits

As surveillance and censoring technologies advance, so, too, do new tools for your computer or mobile device that help protect your privacy and break through Internet censorship.
More