LookBack is a custom Windows remote access Trojan associated with targeted espionage activity against the electric utilities sector, particularly in the United States, during 2019. It has been linked to the TALONITE activity group and also associated with TA410, especially the LookingFrog subgroup. The malware was used in spearphishing campaigns that impersonated engineering and certification organizations and delivered malicious Microsoft Word documents containing VBA macros.
LookBack is a multi-component malware family comprising a RAT module, a communications module, a malicious loader implemented through a modified library, and a proxy component that masquerades as legitimate software. The loader side-loads the communications module, decrypts embedded malicious data, and launches the backdoor functionality. Communications are relayed through a local proxy mechanism and protected with a modified RC4-based scheme. The RAT supports host reconnaissance and active remote control, including process enumeration, system and file inspection, command execution, screenshot capture, file deletion, reboot control, and self-deletion. Reported functionality also includes user activity monitoring and credential capture.
For persistence, LookBack establishes Registry Run-based autorun execution at user logon. It has also been observed using DLL side-loading as part of its execution chain. The malware employs defense-evasion measures including masquerading as legitimate software components, use of modified legitimate binaries, encrypted or encoded payload handling, and cleanup through self-removal and file deletion.
Operational reporting indicates LookBack was used primarily for initial access support and information gathering rather than confirmed disruptive industrial control system operations. Targeting has centered on electric utilities, and available reporting has not established confirmed intrusion into control system networks or disruptive effects. Attribution remains cautious: multiple analyses note tradecraft overlap with activity historically associated with APT10, but definitive linkage has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group uses phishing techniques with either malicious documents or executables. TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud.
rule apt_Windows_TA410_LookBack_decryption ... description = "Matches encryption/decryption function used by LookBack." ... rule apt_Windows_TA410_LookBack_loader ... description = "Matches the modified function in LookBack libcurl loader." ... rule apt_Windows_TA410_LookBack_HTTP ... description = "Matches LookBack's hardcoded HTTP request"
From August to September 2019, researchers at Proofpoint identified a phishing campaign they call LookBack, utilizing spoofed network infrastructure and emails to deliver malware to electric utilities.
Proofpoint researchers reported that LookBack malware was targeting the United States (U.S.) utilities sector between July and August 2019... both LookBack and FlowCloud malware can be attributed to a single threat actor we are calling TA410.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on the capabilities of LookBack and FlowCloud, both of which facilitate various means of credential capture, Dragos assesses with high confidence that TALONITE lateral movement incorporates credential reuse.
Exploit public facing app: LookingFrog and JollyFrog • CVE-2019-0604 • ProxyLogon (March 2021) • ProxyShell (August 2021)
The group uses phishing techniques with either malicious documents or executables.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Based on the capabilities of LookBack and FlowCloud, both of which facilitate various means of credential capture, Dragos assesses with high confidence that TALONITE lateral movement incorporates credential reuse.
Both malware types are Remote Access Trojans (RAT) that contain capabilities to establish persistence within the environment.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Based on the capabilities of LookBack and FlowCloud, both of which facilitate various means of credential capture, Dragos assesses with high confidence that TALONITE lateral movement incorporates credential reuse.
Both malware types are Remote Access Trojans (RAT) that contain capabilities to establish persistence within the environment.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
threat actors appeared to utilize many concatenation commands within the macro to obfuscate the VBA function. It is possible these concatenations were an attempt to evade static signature detection for the macro strings...
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
TALONITE TTPs from MITRE ATT&CK ... DISCOVERY ... T1046 Network Scanning Service
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses VBA macros in Word attachments to drop additional files.
Malware that establishes persistence through a Registry Run key.
Malware with a C2 proxy component disguised as a legitimate Notepad++ updater.
Backdoor malware with functionality to decrypt malicious data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.