Description
LookBack is a C++ remote access trojan used against at least three US utility companies in July 2019, with the TALONITE activity group observed deploying it.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
Lookback
MITRE ATT&CK techniques
16 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0009 Collection
- T1113Screen Capture
TA0011 Command and Control
Alert name variants
| Alert Name |
|---|
| Document-Word.Backdoor.LookBack |
| Win32.Backdoor.Lookback |
| Win32.Backdoor.LookBack |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Generic.Lookback.malware.c2 traffic detected |