LookBack

MITRE ATT&CK: S0582 View on attack.mitre.org

Aliases: LookBack

First seen
2019-07-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:39:28

Targeted industries: energy-and-utilities

Targeted regions: country_code:us

Context

LookBack is a remote access trojan written in C++ that was used against at least three US utility companies in July 2019. The TALONITE activity group has been observed using LookBack.

Detection coverage

  • 6 YARA rules
  • 308 Sigma rules

Malware & tools used

  • Service Stop (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Web Protocols (attack-pattern)
  • Screen Capture (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • File Deletion (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • DLL (attack-pattern)

Detection rules

  • ESET_Apt_Windows_TA410_Lookback_Decryption (yara-rule)
  • ESET_Apt_Windows_TA410_Lookback_Loader (yara-rule)
  • ESET_Apt_Windows_TA410_Lookback_Strings (yara-rule)
  • ESET_Apt_Windows_TA410_Lookback_HTTP (yara-rule)
  • ESET_Apt_Windows_TA410_Lookback_Magic (yara-rule)
  • MALPEDIA_Win_Lookback_Auto (yara-rule)

Reports & references

  • proofpoint.com — Ta410 Group Behind Lookback Attacks Against Us Utilities Sector Returns New (report)
  • proofpoint.com — Lookback Forges Ahead Continued Targeting United States Utilities Sector Reveals (report)
  • proofpoint.com — Lookback Malware Targets United States Utilities Sector Phishing Attacks (report)
  • Broadcom/Symantec — Witchetty Steganography Espionage (report)
  • ESET — Lookback Ta410 Umbrella Cyberespionage Ttps Activity (report)
  • ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
  • pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
  • nao-sec.org — Royal Road Redive (report)
  • botconf.eu — Botconf2022 19 Faoucotecyr (report)
  • dragos.com — New Ics Threat Activity Group Talonite (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lookback (report)
  • threatgen.com — Taking A Closer Look At The Lookback Malware Campaign Part 1 (report)
  • hub.dragos.com — Dragos 2020 Ics Cybersecurity Year In Review (report)
  • MITRE ATT&CK — S0582 (report)
  • dragos.com — Talonite (report)

External references