Back to News
Market Impact: 0.45

Mysterious hacking group Careto was run by the Spanish government, sources say

NOK
Cybersecurity & Data PrivacyGeopolitics & WarTechnology & Innovation

Kaspersky researchers, who initially discovered the Spanish-speaking hacking group Careto in 2014, internally concluded that it was a hacking team working for the Spanish government, though this attribution was never made public. Careto, known for its sophisticated malware capable of stealing sensitive data, targeted government institutions and private companies globally, with a particular focus on Cuba, which sparked the initial investigation due to the presence of Basque terrorist organization ETA members there. While Kaspersky publicly avoided blaming any specific government, it recently detected Careto's malware again in 2024, targeting organizations in Latin America and Central Africa, but still cannot definitively attribute the attacks to a specific nation state.

Analysis

Internal conviction among Kaspersky researchers, dating back to the 2014 discovery of the hacking group Careto, attributed its sophisticated cyber-espionage operations to the Spanish government, although Kaspersky maintained a public policy of no formal attribution. Careto, named after a Spanish slang term found in its malware, was described as one of the most advanced threats at the time, capable of exfiltrating highly sensitive data, including private conversations and keystrokes, from government institutions and private companies globally. The initial investigation was notably sparked by the targeting of a Cuban government institution, a region where Basque terrorist group ETA members were present, aligning with Spain's geostrategic interests, alongside other targets like Gibraltar and Brazil. Despite dismantling its infrastructure post-discovery in 2014, Careto re-emerged by 2024, with Kaspersky identifying new attacks leveraging similarly complex malware against organizations in Latin America and Central Africa, some of which were previous victims. Current Kaspersky analysis reaffirms Careto's high level of sophistication, describing its recent attacks as a 'masterpiece' in complexity, likely state-sponsored, though still without public government attribution. The group's tactics included spearphishing with links impersonating Spanish newspapers and exploiting vulnerabilities, including one in Kaspersky's own antivirus software, which ironically aided its discovery due to Kaspersky's dominant market share in Cuba.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.50

Ticker Sentiment

NOK-0.10

Key Decisions for Investors

  • Investors should factor in the persistent and evolving threat of highly sophisticated, potentially state-sponsored cyber-espionage groups like Careto, particularly when assessing risks for companies with significant international operations, sensitive data, or involvement in critical infrastructure.
  • The re-emergence and continued complexity of Careto's operations underscore the increasing necessity for advanced cybersecurity solutions, potentially signaling sustained growth and investment opportunities within the cybersecurity sector.
  • The reported internal belief that a Western government (Spain) was behind Careto broadens the recognized spectrum of state actors engaged in cyber operations, requiring a more nuanced geopolitical risk assessment for multinational corporations beyond traditional threat actor profiles.