🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)

🎥 IT Security Video 🕛 vor 1 Jahr 2 Min Lesezeit SECURITY-FEED
0

Youtube virusbtn: The Mask has been unmasked again - Georgy Kucherin & Marc Rivero López

↗ Quelle (YouTube)
🗣️ Stimme:
📺
YouTube
1k YouTube-Aufrufe

Author: Virus Bulletin - Bewertung: 0x - Views:0

Presented at the VB2024 conference in Dublin, 2 - 4 October 2024.

↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/slides/Slides-The-Mask-has-been-unmasked-again.pdf

↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/The-Mask-has-been-unmasked-again.pdf

→ Details: https://www.virusbulletin.com/conference/vb2024/abstracts/mask-has-been-unmasked-again/



✪ PRESENTED BY ✪



• Georgy Kucherin (Kaspersky)

• Marc Rivero López (Kaspersky)



✪ ABSTRACT ✪



The Mask (also known as Careto) is an advanced threat actor that has been operating since at least 2007. In the past, it was observed to conduct cyberespionage campaigns that mainly targeted high-profile organizations. Attacks of this actor have always been remarkable from the technical perspective, as they commonly involve use of zero-day exploits, bootkits, and modular backdoors for different operating systems.



Over the last decade, the Mask has been doing its best to avoid getting caught by researchers: since 2014 there has not been any information about the group. Nevertheless, in our recent research we have managed to uncover a number of new campaigns of this threat actor – with the latest dated up to early 2024. In our paper we provide details about these campaigns, focusing on how the Mask has been achieving initial access, lateral movement, malware execution, and data exfiltration.



Specifically, we first describe how the Mask leveraged the MDaemon email server of one of the target organizations to gain an initial foothold inside it. We then detail how this threat actor used a previously unknown bug in a security solution to covertly spread malicious implants across machines. Afterwards, we discuss capabilities of the delivered implants, as well as the stealth measures implemented inside them.



The Mask has always conducted cyber attacks with extreme caution. Despite this, members of this threat group have still managed to make small but fatal mistakes during their recent operations. In the paper, we describe these errors, specifying how they helped not only detect the discussed malicious activities, but also perform attribution of the discovered campaigns.



At the end of our paper we present a comparison between the historical and recent attacks of The Mask to demonstrate how the operations of the group have evolved over the years.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
ChatGPT automatically logged out [Fix]
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The Mask has been unmasked again - Georgy Kucherin & Marc Rivero López

Thematisch verwandte Begriffe: Mask, been, unmasked, again · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...