LookBack

S0582

Malware.View on attack.mitre.org

About this malware

LookBack is a remote access trojan written in C++ that was used against at least three US utility companies in July 2019. The TALONITE activity group has been observed using LookBack.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1007
System Service Discovery

LookBack can enumerate services on the victim machine.

T1036.005
Match Legitimate Resource Name or Location

LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.

T1057
Process Discovery

LookBack can list running processes.

T1059.003
Windows Command Shell

LookBack executes the cmd.exe command.

T1059.005
Visual Basic

LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host.

T1070.004
File Deletion

LookBack removes itself after execution and can delete files on the system.

T1071.001
Web Protocols

LookBack’s C2 proxy tool sends data to a C2 server over HTTP.

T1083
File and Directory Discovery

LookBack can retrieve file listings from the victim machine.

T1095
Non-Application Layer Protocol

LookBack uses a custom binary protocol over sockets for C2 communications.

T1113
Screen Capture

LookBack can take desktop screenshots.

T1140
Deobfuscate/Decode Files or Information

LookBack has a function that decrypts malicious data.

T1489
Service Stop

LookBack can kill processes and delete services.

T1529
System Shutdown/Reboot

LookBack can shutdown and reboot the victim machine.

T1547.001
Registry Run Keys / Startup Folder

LookBack sets up a Registry Run key to establish a persistence mechanism.

T1573.001
Symmetric Cryptography

LookBack uses a modified version of RC4 for data transfer.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Dragos TALONITE Open source
    Dragos. (null). TALONITE. Retrieved February 25, 2021.
  2. Dragos Threat Report 2020 Open source
    Dragos. (n.d.). ICS Cybersecurity Year in Review 2020. Retrieved February 25, 2021.
  3. Proofpoint LookBack Malware Aug 2019 Open source
    Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.