Early in August 2019, Proofpoint described what appeared to be state-sponsored activity targeting the US utilities sector with malware that we dubbed “Lookback”. Between August 21 and August 29, 2019, several spear phishing emails were identified targeting additional US companies in the utilities sector. The phishing emails originated from what appears to be an actor-controlled domain: globalenergycertification[.]net. This domain, like those used in previous campaigns, impersonated a licensing body related to the utilities sector. In this case, it masqueraded as the legitimate domain for Global Energy Certification (“GEC”). The emails include a GEC examination-themed body and a malicious Microsoft Word attachment that uses macros to install and run LookBack. (Note confusion between Malware, Campaign and ThreatActor)
Executive Summary
TA410 is suspected state-sponsored threat actor targeting US utilities through sophisticated phishing campaigns. Their primary tactic involves spear-phishing emails with malicious Microsoft Word attachments that deploy custom malware to compromise critical infrastructure sectors.
Goals & Targeting
TA410 appears to target the US utilities sector strategically, potentially aiming to disrupt or gain unauthorized access to critical infrastructure. Their choice of victims suggests a focus on industries that could pose significant risks to national security if compromised. The use of state-sponsored tactics indicates a likely intent to gather intelligence or execute disruptive activities.
Enhanced Description
TA410, also referred to as a state-sponsored actor, has demonstrated significant focus on the US utilities sector. In August 2019, Proofpoint identified TA410's activity through a campaign dubbed 'Lookback,' which used spear-phishing emails to target multiple US companies in the utilities sector. The phishing emails were crafted to appear as official communications from Global Energy Certification (GEC), leveraging the domain globalenergycertification.net. These emails contained malicious Microsoft Word documents with宏(hé) malware, designed to execute Lookback on compromised systems. TA410's ability to impersonate legitimate entities and remain undetected for extended periods highlights their sophistication in targeting critical infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA410's campaign in August 2019 demonstrated a persistent and targeted approach, indicating a possible long-term operational strategy. The use of a specific domain (globalenergycertification.net) to impersonate GEC suggests careful planning and a focus on credibility. This actor’s targeting patterns and techniques align with state-sponsored activity aiming to compromise critical infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in TA410's state-sponsored status and utility sector targeting due to specific campaign activities. Limited details on their long-term objectives, affiliations, and other campaigns outside 2019.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics