Kaspersky Researchers Link Advanced Espionage Group ‘Careto’ to Spanish Government
A decade after its initial discovery, cybersecurity researchers have reaffirmed that the advanced hacking group ‘Careto’—also known as ‘The Mask’—was likely operated by the Spanish government. Originally identified by antivirus company Kaspersky in 2014, Careto deployed sophisticated malware capable of stealing sensitive information from targets worldwide, including government bodies, energy firms, and research institutions. Although Kaspersky never publicly attributed the attacks, former employees have now disclosed that internal investigations pointed to Spanish state involvement with high confidence.
Careto first caught Kaspersky’s attention when targeting a Cuban government institution, with suspicions reinforced by the group’s Spanish-language code and interest in regions aligned with Spain’s strategic and political interests, such as Gibraltar and Brazil. The group notably used spearphishing campaigns disguised as Spanish news sites, and the malware itself contained Spanish expletives. Its activity ceased shortly after public exposure in 2014 but reemerged in 2022 and 2024 with similar tools and techniques. Kaspersky recently detected new infections in Latin America and Central Africa, indicating that Careto’s operations continue, albeit more cautiously. Despite strong evidence, Kaspersky maintains a policy of non-attribution, and neither the Spanish nor Cuban governments have commented on the findings.
