Is this the most advanced malware ever?

Status
Not open for further replies.

Tony Cole

Level 27
Thread author
Verified
May 11, 2014
1,639
I found this on Bleeping Computer:

HOLY CRAP...HERE'S THE BIG ONE!!!!

this malware has been around a couple of months but has a massive target list... it targets governments, military bases and the gas company that you always go to down the road. It's called "the mask" or "careto" as some people call it

As kaspersky lab has said " What makes The Mask special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated malware, a rootkit, a bootkit, Mac OS X and Linux versions and possibly versions for Android and iOS (iPad/iPhone). The primary targets are government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists. Victims of this targeted attack have been found in 31 countries around the world – from the Middle East and Europe to Africa and the Americas."

Now you have to admit it is BADASS and the author is still unknown...They think the author is native to spanish language and that's all they know about the author, Kaspersky labs analysis report "The Mask campaign relies on spear-phishing e-mails with links to a malicious website. The malicious website contains a number of exploits designed to infect the visitor, depending on system configuration. Upon successful infection, the malicious website redirects the user to the benign website referenced in the e-mail, which can be a YouTube movie or a news portal."

More can be found here.

http://www.kaspersky.com/about/news...mplexity-of-the-Toolset-Used-by-the-Attackers

and here

http://www.itproportal.com/2014/02/...ost-advanced-malware-threats-ever-discovered/
 

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
I found this on Bleeping Computer:

HOLY CRAP...HERE'S THE BIG ONE!!!!

this malware has been around a couple of months but has a massive target list... it targets governments, military bases and the gas company that you always go to down the road. It's called "the mask" or "careto" as some people call it

As kaspersky lab has said " What makes The Mask special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated malware, a rootkit, a bootkit, Mac OS X and Linux versions and possibly versions for Android and iOS (iPad/iPhone). The primary targets are government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists. Victims of this targeted attack have been found in 31 countries around the world – from the Middle East and Europe to Africa and the Americas."

Now you have to admit it is BADASS and the author is still unknown...They think the author is native to spanish language and that's all they know about the author, Kaspersky labs analysis report "The Mask campaign relies on spear-phishing e-mails with links to a malicious website. The malicious website contains a number of exploits designed to infect the visitor, depending on system configuration. Upon successful infection, the malicious website redirects the user to the benign website referenced in the e-mail, which can be a YouTube movie or a news portal."

More can be found here.

http://www.kaspersky.com/about/news...mplexity-of-the-Toolset-Used-by-the-Attackers

and here

http://www.itproportal.com/2014/02/...ost-advanced-malware-threats-ever-discovered/

Thanks for the share, Tony!
I read this aloud to my wife as she spread our toast with jelly.:):)
as always , primary infection vector is the user.
O Hyperborean Traveler Umbra, would sandboxie's or Shadow Defender's protections prevent said 'user' from transforming oneself into an :eek:'infection vector'?
 

Tony Cole

Level 27
Thread author
Verified
May 11, 2014
1,639
Well it's a Nation State developed Malware, so I doubt any security measures us mere mortals could deploy would stop it. This world and internet is getting scarier as the days go by. One famous quote comes to mind "The Internet is the first thing that humanity has built that humanity doesn't understand, the largest experiment in anarchy that we have ever had."
 
  • Like
Reactions: Cats-4_Owners-2

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Well it's a Nation State developed Malware, so I doubt any security measures us mere mortals could deploy would stop it. This world and internet is getting scarier as the days go by. One famous quote comes to mind "The Internet is the first thing that humanity has built that humanity doesn't understand, the largest experiment in anarchy that we have ever had."
Agreed.:oops:
I am amazed how such beautifully poetic statements can be created to express what people do when unleashed, en mass, brazenly upon any new world; and it's being worded far more eloquently than the harsh fact that we irresponsibly use, & forever alter, every new environment we are ever fortunate enough to discover.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Usually nasty/advance viruses can be meet depends on its range therefore rootkit/bootkit are always considered dangerous and especially compatible to more than one OS since it reflects already for vulnerabilities.
 
  • Like
Reactions: Cats-4_Owners-2
D

Deleted member 178

dont understimate the power of Shadow Defender !!! i counted 3 malwares that bypassed it , while it doesn't have the MBR protection implemented yet.

now if this malware, is able to reach the Bios , SD will be useless like any other AV.
 
Last edited by a moderator:
  • Like
Reactions: Cats-4_Owners-2

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
dont understimate the power of Shadow Defender !!! i counted 3 aware that bypassed it , while it doesn't have the MBR protection implemented yet.

now if this malware, is able to reach the Bios , SD will be useless like any other AV.

:eek:eek!
 
H

hjlbx

dont understimate the power of Shadow Defender !!! i counted 3 malwares that bypassed it , while it doesn't have the MBR protection implemented yet.

Which ones\types?

I've searched everywhere - and - can find no absolutely confirmable cases of SD "bypass."

The single case I am referring to is the rootkit remnant found by Kaspersky TDSSKiller (the Polish video from a few years ago).
 
Last edited by a moderator:
  • Like
Reactions: Cats-4_Owners-2
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top