LookBack is a modular, C++ remote access Trojan for Windows used in cyberespionage and information-gathering operations, notably against U.S. electric utilities in campaigns identified in 2019. It is associated with TA410, including its LookingFrog subgroup, and with activity tracked as TALONITE. Observed delivery involved spearphishing emails impersonating engineering, licensing, and energy-certification organizations. Malicious Microsoft Word attachments used obfuscated VBA macros to drop, decode, and execute its components.
LookBack combines a remote-access module, a communications module, a modified library loader, and a command-and-control proxy. Its communications module uses a custom binary socket protocol and modified RC4 encryption to exchange data with a local proxy, which forwards traffic to external command-and-control infrastructure over HTTP. The proxy masquerades as a legitimate Notepad++ updater, while the loader decrypts and loads embedded malicious components. LookBack uses DLL side-loading and registry-based logon persistence.
Its capabilities include collecting system, process, service, and file information; capturing desktop screenshots and credentials; executing commands; controlling the mouse; deleting files; rebooting the host; and removing itself. These functions support host surveillance and remote control. Although deployed against utilities, the documented TALONITE activity did not establish penetration of control-system networks or disruptive ICS operations. Similarities to APT10 tradecraft do not establish attribution to APT10 or a particular state sponsor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group uses phishing techniques with either malicious documents or executables. TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud.
rule apt_Windows_TA410_LookBack_decryption ... description = "Matches encryption/decryption function used by LookBack." ... rule apt_Windows_TA410_LookBack_loader ... description = "Matches the modified function in LookBack libcurl loader." ... rule apt_Windows_TA410_LookBack_HTTP ... description = "Matches LookBack's hardcoded HTTP request"
From August to September 2019, researchers at Proofpoint identified a phishing campaign they call LookBack, utilizing spoofed network infrastructure and emails to deliver malware to electric utilities.
Proofpoint researchers reported that LookBack malware was targeting the United States (U.S.) utilities sector between July and August 2019... both LookBack and FlowCloud malware can be attributed to a single threat actor we are calling TA410.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
Both malware types are Remote Access Trojans (RAT) that contain capabilities to establish persistence within the environment.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Both malware types are Remote Access Trojans (RAT) that contain capabilities to establish persistence within the environment.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses VBA macros in Word attachments to drop additional files.
Uses a custom binary protocol over sockets for command and control. A cited report describes phishing attacks targeting the United States utilities sector.
Malware with a C2 proxy component disguised as a legitimate Notepad++ updater.
Backdoor malware with functionality to decrypt malicious data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.