LookBack is a custom multi-component Windows remote access Trojan (RAT) first reported by Proofpoint in 2019 in spearphishing campaigns targeting the U.S. utilities sector, particularly electric utilities. It was delivered via malicious Microsoft Word attachments using VBA macros, including lures such as "Result Notice.doc" and "take the exam now.doc," sent from spoofed engineering- and certification-themed domains including nceess[.]com and globalenergycertification[.]net. Proofpoint identified at least 17 U.S. utilities entities targeted from April through August 2019, and Dragos later associated LookBack with the TALONITE activity group; Proofpoint assessed both LookBack and FlowCloud were likely operated by TA410. Dragos reported behavioral overlap between TALONITE and APT10 but stated attribution was not definitive.
The infection chain used obfuscated VBA macros to drop PEM-formatted files and a certutil variant, then decode and restore components including GUP.exe, a malicious libcurl.dll loader, and configuration data such as sodom.txt. LookBack consists of at least a communications module called SodomNormal and a RAT module called SodomMain. The malicious libcurl.dll side-loads the communications module through a modified exported function (#52 / curl_share_init), which extracts and decrypts embedded malicious data and loads the next-stage DLL. Persistence was established via HKCU\Software\Microsoft\Windows\CurrentVersion\Run with the value CurlUpdate executing rundll32.exe C:\Users\Public\libcurl.dll,#52.
For command and control, LookBack uses a proxy mechanism in which GUP.exe masquerades as a legitimate Notepad++-related binary and relays traffic between the infected host and external infrastructure. The malware uses a custom binary protocol over sockets and a modified RC4 algorithm for encrypted data transfer. Reported C2 infrastructure included 103.253.41[.]45, and one observed beacon pattern was http://%s/status[.]gif?r=%d.
Documented capabilities include enumerating services; viewing process, system, and file information; deleting files; executing commands; taking desktop screenshots; controlling the mouse; shutting down or rebooting the victim machine; and self-deletion. The campaigns were described as significant to critical infrastructure because they focused on initial access and host control within the U.S. electric sector. Additional reported infrastructure and delivery indicators include phishing source IPs 79.141.168[.]137 and 79.141.169[.]3, staging IP 103.253.41[.]75, and the spoofed domains nceess[.]com and globalenergycertification[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers reported that LookBack malware was targeting the United States (U.S.) utilities sector between July and August 2019... both LookBack and FlowCloud malware can be attributed to a single threat actor we are calling TA410.
Proofpoint researchers reported that LookBack malware was targeting the United States (U.S.) utilities sector between July and August 2019... both LookBack and FlowCloud malware can be attributed to a single threat actor we are calling TA410.
Proofpoint researchers reported that LookBack malware was targeting the United States (U.S.) utilities sector between July and August 2019... both LookBack and FlowCloud malware can be attributed to a single threat actor we are calling TA410.
"TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Between July 19 and July 25, 2019, several spear phishing emails were identified targeting three US companies in the utilities sector... The emails contain a malicious Microsoft Word attachment that uses macros to install and run malware that Proofpoint researchers have dubbed “LookBack.”
cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v CurlUpdate /f /d rundll32.exe C:\Users\Public\libcurl.dll,#52
threat actors appeared to utilize many concatenation commands within the macro to obfuscate the VBA function. It is possible these concatenations were an attempt to evade static signature detection for the macro strings...
tempgup.txt becomes GUP.exe, which impersonates the name of an open-source binary used by Notepad++; tempgup2.txt becomes libcurl.dll... In this campaign, files appeared to impersonate the GUP.exe file name rather than being a legitimate signed binary.
Akira has used legitimate names and locations for files to evade defenses.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
Its capabilities include an enumeration of services; viewing of process, system, and file data...
Its capabilities include an enumeration of services; viewing of process, system, and file data...
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Analysts have determined that the LookBack samples from recent campaigns utilize the same command and control (C&C) server, 103.253.41[.]45, observed in July campaigns. The LookBack beacon is identifiable via the URL format below: C&C URL format: http://%s/status[.]gif?r=%d
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
This malware consists of a remote access Trojan (RAT) module and a proxy mechanism used for command and control (C&C) communication... The function of this tool is to set up a TCP listener on a localhost, receive encoded data via requests from the SodomNormal localhost module, and to forward this data to the command and control IP via HTTP.
When the attachment is executed, the malicious VBA macro within the Microsoft Word attachment drops three Privacy Enhanced Mail (PEM) files to the host... Finally, the macro launches GUP.exe and the libcurl.dll loader separately, resulting in the execution of LookBack malware.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LookBack is a modular malware family used in phishing campaigns against U.S. utility providers. It was delivered via malicious macro-laden Word documents and provided remote access capability as part of TA410 operations.
Custom malware delivered via spear-phishing Word documents with VBA macros. The infection chain drops and decodes multiple modules, including a GUP proxy tool, a malicious libcurl.dll loader, and Sodom modules that configure a local host proxy and provide remote access trojan functionality.
A C++ remote access trojan delivered via malicious Word macros in spear-phishing emails. It uses a loader and local proxy-based C2 architecture, supports service/process/system/file enumeration, file deletion, command execution, screenshots, mouse control, reboot, self-deletion, and file operations through its SodomMain RAT module.
Malware delivered through Word attachments with VBA macros that drop additional files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.