Can you please tell me more about The Mask -- which some are touting as the "most advanced malware around"? How...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
much of a threat is it to the average enterprise and what defenses will work against it?
The Mask (aka Careto) may currently be the most advanced publicly known malware, but it will undoubtedly be surpassed by malware that comes out in the future. However, The Mask can be credited with successfully incorporating multiple cutting-edge attack techniques. The Mask also appears to use some general good-programming practices; for example, it incorporates modular development into the design and allows for modules to be updated or new modules to be deployed after it has infiltrated a system. This can help hide the malware. Once malware developers know certain components are being detected by antimalware tools, they can deploy an updated module to replace the detected one. The Mask also can disable antimalware tools in victims' systems by preventing the antimalware tool from scanning the malicious file or by disabling the tools outright from running on the system.
The good thing for most enterprises is that The Mask is a targeted attack and appears to have had fewer than 400 victims and to have infected in the range of 1,000 IPs. While the names of the victims have not been released, their country and industry sectors have been. The Mask is also targeting systems with older antimalware software, so running current versions of antimalware tools on endpoints may potentially block and prevent the attack.
One study on The Mask includes indicators of compromise including specific IP addresses, Domain Name System names and file names that could be used to detect whether your system is infected by the malware. It looks as if The Mask is trying to collect sensitive data by seeking file types on endpoints, so monitoring your local system with a file integrity monitor for a high amount of suspicious file-system activity could also produce something to investigate.
Ask the Expert!
Want to ask Nick Lewis a question about enterprise threats? Submit your question now via email! (All questions are anonymous.)
Dig Deeper on Malware, Viruses, Trojans and Spyware
Related Q&A from Nick Lewis
An HTTPS session with a reused nonce is vulnerable to the Forbidden attack. Expert Nick Lewis explains how the attack works, and how to properly ...continue reading
The Irongate malware has been discovered to have similar functionality to Stuxnet. Expert Nick Lewis explains how enterprises can protect their ICS ...continue reading
APT groups have been continuously exploiting a flaw in Microsoft Office, despite it having been patched. Expert Nick Lewis explains how these attacks...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.