'The Mask' cyber-espionage campaign operating undetected since 2007: Kaspersky Lab

Advertisement
By Reuters | Updated: 11 February 2014 12:34 IST
A computer security software firm has uncovered what it calls the first cyber-espionage campaign believed to be started by a Spanish-speaking country, targeting government agencies, energy companies and activists in 31 countries.

Dubbed "The Mask," the campaign had operated undetected since 2007 and infected more than 380 targets before it stopped last week, Moscow-based Kaspersky Lab said on Monday.

The firm declined to identify the government suspected to be behind the cyber-spying, but said it had been most active in Morocco, followed by Brazil, the United Kingdom, France and Spain.

The suspected involvement of a Spanish-speaking nation is unusual as the most sophisticated cyber spying operations uncovered so far have been linked to the United States, China, Russia and Israel. Those nations have been said to be behind the Duqu, Gauss and Flame malware, for example.

Advertisement

Kaspersky Lab said the discovery of The Mask suggests that more countries have become adept in Internet spying. The firm's researchers only came across the operation because it infected Kaspersky's own software.

Advertisement

"There are many super-advanced groups that we don't know about. This is the tip of the iceberg," Costin Raiu, director of Kaspersky's global research team, said in an interview on the sidelines of a conference sponsored by his company in the Dominican Republic.

Raiu said The Mask hit government institutions, oil and gas companies and activists, using malware that was designed to steal documents, encryption keys and other sensitive files, as well as take full control of infected computers.

Advertisement

The operation infected computers running Microsoft Corp's Windows and Apple Inc's Mac software, and likely mobile devices running Apple's iOS and Google Inc's Android software, according to Kaspersky Lab.

The companies did not immediately respond to requests for comment.

Advertisement

Kaspersky Lab said it worked with Apple and other companies last week to shut down some of the websites that were controlling the spying operation.

The Russian-based company named the operation "The Mask" for the translation of the Spanish word "Careto," which appears in the malware code.

Among other things, The Mask hackers took advantage of a known flaw in Adobe Systems Inc's ubiquitous Flash software that permitted attackers to get from Google's Chrome web browser into the rest of a target's computer, Raiu said. Adobe fixed the flaw in 2012, he said.

A spokeswoman for Adobe confirmed that the company released an update to Flash in April 2012 that fixed the vulnerability. She declined to comment on Kaspersky Lab's research on The Mask.

Raiu said The Mask attackers may have been aided by a booming grey market for undisclosed software flaws and the tools for exploiting them, known as "zero-day" exploits because the makers of affected software have no notice of the danger. Buyers of zero-days often leave the software vulnerabilities unfixed in order to deploy spy software.

The Flash flaw had been uncovered in 2012 by a Paris-based company called Vupen, which specializes in finding such weaknesses. Vupen revealed the vulnerability at a hacking competition that year, but did not demonstrate how it can be exploited. Instead, Vupen said it would sell its research to its government clients.

Kaspersky Lab said The Mask was one of the few Internet spying campaigns exposed to date that appear to have links to a zero-day sale. Vupen Chief Executive Chaouki Bekrar disputed any connection to his company.

"Believe it or not, but there are many other companies selling zero-days," Vupen said via email.

Security experts have become increasingly concerned about the zero-day market, where governments including the United States are active buyers. A former top U.S. cyber-security official, Richard Clarke, says that deliberately leaving vulnerabilities unfixed puts U.S. assets at risk.

Liam O'Murchu, a researcher at Symantec Corp, said it was difficult to know who was behind The Mask.

"Just looking at the targets, it is not obvious who would want to target them; there is no obvious pattern," O'Murchu said via email. "The code is professionally written, but it's even difficult to say whether is it written by a government or by a private company that sells this type of software."

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 Arrives on Geekbench With This Snapdragon Chipset
  2. Here's Why the OnePlus 15 Won't Sport a 2K Resolution Display
  3. Redmi K90 Pro Max, Redmi K90 Launched With Bose Audio: See Price, Features
  4. Garmin D2 Air X15, Garmin D2 Mach 2 Launched With PlaneSync Technology
  5. Next-Gen Xbox Will Be 'Very Premium, Very High-End Curated Experience'
  6. Microsoft Is Upgrading Copilot With These New Features
  7. Vivo X300 Series Surfaces on BIS Website, Could Launch in India Soon
  8. Here's When the Vivo X300 Pro and Vivo X300 Could Launch in India
  9. OnePlus Tipped to Launch New Smartphone With This Upcoming Qualcomm Chip
  10. UK's FCA Warns Hundreds of Crypto Exchanges Over Compliance
  1. Microsoft Introduces Major Copilot Upgrade, Brings Avatar, Groups and Health Features
  2. Next-Gen Xbox Will Be 'Very Premium, Very High-End Curated Experience', Says Xbox President Sarah Bond
  3. ChatGPT's Voice Mode Could Soon Support Rich Content Including Links, Maps: Report
  4. Redmi Watch 6 Launched With 2.07-Inch AMOLED Screen, Up to 24-Day Battery Life: Price, Features
  5. UK FCA Cracks Down on Crypto Firms, Hundreds of Exchanges Receive Warnings
  6. Google Pixel 10 Series GPU Driver Update Reportedly Confirmed by Company
  7. Honor Magic 8 Lite Key Specifications Revealed via Product Listings, Could Launch Soon
  8. Hong Kong’s Securities Regulator Approves First Spot Solana ETF
  9. Google Photos Is Reportedly Working on a Feature That Turns You Into a Meme
  10. Apple Said to Plan Launch of Foldable iPhone, Bezel-Less iPhone and iPhone Flip
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.