LookBack
MITRE ATT&CK: S0582 View on attack.mitre.org
Aliases: LookBack
- First seen
- 2019-07-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:39:28
Targeted industries: energy-and-utilities
Targeted regions: country_code:us
Context
LookBack is a remote access trojan written in C++ that was used against at least three US utility companies in July 2019. The TALONITE activity group has been observed using LookBack.
Detection coverage
- 6 YARA rules
- 308 Sigma rules
Malware & tools used
- Service Stop (attack-pattern)
- Windows Command Shell (attack-pattern)
- Visual Basic (attack-pattern)
- System Service Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- Screen Capture (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- File Deletion (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- DLL (attack-pattern)
Detection rules
- ESET_Apt_Windows_TA410_Lookback_Decryption (yara-rule)
- ESET_Apt_Windows_TA410_Lookback_Loader (yara-rule)
- ESET_Apt_Windows_TA410_Lookback_Strings (yara-rule)
- ESET_Apt_Windows_TA410_Lookback_HTTP (yara-rule)
- ESET_Apt_Windows_TA410_Lookback_Magic (yara-rule)
- MALPEDIA_Win_Lookback_Auto (yara-rule)
Reports & references
- proofpoint.com — Ta410 Group Behind Lookback Attacks Against Us Utilities Sector Returns New (report)
- proofpoint.com — Lookback Forges Ahead Continued Targeting United States Utilities Sector Reveals (report)
- proofpoint.com — Lookback Malware Targets United States Utilities Sector Phishing Attacks (report)
- Broadcom/Symantec — Witchetty Steganography Espionage (report)
- ESET — Lookback Ta410 Umbrella Cyberespionage Ttps Activity (report)
- ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
- pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
- nao-sec.org — Royal Road Redive (report)
- botconf.eu — Botconf2022 19 Faoucotecyr (report)
- dragos.com — New Ics Threat Activity Group Talonite (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lookback (report)
- threatgen.com — Taking A Closer Look At The Lookback Malware Campaign Part 1 (report)
- hub.dragos.com — Dragos 2020 Ics Cybersecurity Year In Review (report)
- MITRE ATT&CK — S0582 (report)
- dragos.com — Talonite (report)