Careto (The Mask) is a sophisticated, unattributed Spanish-speaking espionage actor exposed by Kaspersky in 2014, active from around 2007, whose global victim set included a notable concentration in Morocco — the basis for its inclusion here, though its MENA nexus is thin and secondary to a broader global campaign.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Careto — Spanish slang for 'ugly face', found in the malware — was disclosed by Kaspersky in February 2014 as one of the most advanced espionage operations then seen, active since roughly 2007. Kaspersky assessed a nation-state-level actor and noted Spanish-language artifacts (unusual among APTs), but did not attribute it to a specific country; it remains unattributed and has no MITRE Group ID. Confidence is medium on capability/sophistication but the MENA angle specifically is thin and is flagged as such: Careto was a global campaign, and its regional relevance rests mainly on a victim concentration in Morocco.
The group's tradecraft was highly advanced for its era: cross-platform implants (Windows, macOS, Linux, with suspected iOS/Android components), exploitation including an Adobe Flash zero-day, rootkit and bootkit-grade stealth, and interception of network traffic, keystrokes, Skype, encryption keys, SSH keys, and VPN configurations. Careful operational security and a rapid shutdown on exposure underscored the actor's professionalism.
MENA relevance is limited and secondary. Among 30+ affected countries, Morocco stood out as one of the most-targeted, alongside victims elsewhere in the region and heavy targeting of Spain, Gibraltar, and Latin America. Targets spanned government institutions, diplomatic offices, energy, and research organizations — but the campaign was global rather than MENA-centric, so its place in a MENA roster is as a peripheral, Morocco-anchored entry.
Careto's infrastructure was dismantled within days of the 2014 disclosure and no further activity was reported for years; it is assessed as retired. (Note: later reporting has revisited possible Careto resurgence, but that is outside this entry's cited scope.) It is included with an explicit thin-MENA-nexus flag and as unattributed.