Menu
'The Mask' malware sets standards hackers are sure to follow

'The Mask' malware sets standards hackers are sure to follow

The hackers' mission is to steal sensitive data, but the capabilities of their malware go far beyond pilfering documents

A recently discovered hacking group called "The Mask" has set a new standard for malware used in sophisticated attacks against government agencies, industry and research organizations, experts say.

On Monday, Kaspersky Lab reported discovering the advanced Spanish-speaking group that has been involved in cyberespionage since at least 2007.

The Mask, aka Careto, has targeted government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists in 31 countries from the Middle East and Europe to Africa and the Americas.

The hackers' mission is to steal sensitive data, but the capabilities of their malware go far beyond pilfering documents. It can also take from networks various encryption keys and authentication keys used in machine-to-machine communications.

"Basically, everything secured and confidential easily becomes available and in a plain text," Dmitry Bestuzhen, head of the research center for Kaspersky Lab in Latin America, said Tuesday.

Versions of the malware were found for Windows, Mac OS X and Linux. Other versions are believed to be capable of infecting Android and iOS mobile devices.

The Mask has built malware that has set a new standard for other hackers to emulate, security experts say.

"It will serve as a model for new cyber-weapon developers worldwide," Tatu Ylonen, chief executive of SSH Communications Security, said. "Future viruses and cyber-weapons will share many of its features."

The discovery of The Mask, which experts say is likely working for a nation-state, is expected to spark a cyber-arms race, Bestuzhev said.

"They certainly will invest more money in new exploit development, trying to align their cyber-arms to the same level as their potential adversaries," he said.

To infect systems, the group started with emails designed to get the recipient to click on a link to a malicious website. The site contained a number of exploits that were downloaded based on the configuration of the visitor's computer.

Following the infection, the visitor was redirected to the benign website referenced in the email, which could be a YouTube movie or news portal.

Because the malware was designed to evade anti-virus software, the best defense would be to catch the malicious app after it is installed.

"This malware highlights how critical it is to audit SSH (machine-to-machine authentication) keys, minimize their number, and regularly change them," Ylonen said.

Kevin Coleman, strategic management consultant for SilverRhino, which specializes in IT security for U.S. government agencies, favored technology that monitors software behavior in the network and warns of unusual activity.

Organizations should also monitor outbound traffic and make sure it is going to known IP addresses, Coleman said.

"We've got to up our game, because of all that's at stake," he said.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securityThe Mask

Featured

Slideshows

Meet the leading customer-centric Microsoft channel partners

Meet the leading customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the leading customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments