← Threat Actors / Spain / Careto
DOSSIER // CARETO

Careto

▲ High Threat Spain
Primary Aliases: Mask The Mask Ugly Face
Sponsor / State Affiliation Spain
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

This threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage purposes. The Mask is an advanced threat actor that has been involved in cyber-espionage operations since at least 2007. The name "Mask" comes from the Spanish slang word "Careto" ("Ugly Face" or “Mask”) which the authors included in some of the malware modules. More than 380 unique victims in 31 countries have been observed to date.What makes “The Mask” special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated malware, a rootkit, a bootkit, 32-and 64-bit Windows versions, Mac OS X and Linux versions and possibly versions for Android and iPad/iPhone (Apple iOS).

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Government Private sector

🛡️ MITRE ATT&CK® Attack Lifecycle (0 TTPs)

📥 Download Navigator JSON
No tactical TTP mapping records recorded in database.

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Copied to clipboard

LINK COPIED TO CLIPBOARD