Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Early in August 2019, Proofpoint described what appeared to be state-sponsored activity targeting the US utilities sector with malware that we dubbed “Lookback”. Between August 21 and August 29, 2019, several spear phishing emails were identified targeting additional US companies in the utilities sector. The phishing emails originated from what appears to be an actor-controlled domain: globalenergycertification[.]net. This domain, like those used in previous campaigns, impersonated a licensing body related to the utilities sector. In this case, it masqueraded as the legitimate domain for Global Energy Certification (“GEC”). The emails include a GEC examination-themed body and a malicious Microsoft Word attachment that uses macros to install and run LookBack. (Note confusion between Malware, Campaign and ThreatActor)

AI Analysis

· 1 week ago

Executive Summary

TA410 is suspected state-sponsored threat actor targeting US utilities through sophisticated phishing campaigns. Their primary tactic involves spear-phishing emails with malicious Microsoft Word attachments that deploy custom malware to compromise critical infrastructure sectors.

Goals & Targeting

TA410 appears to target the US utilities sector strategically, potentially aiming to disrupt or gain unauthorized access to critical infrastructure. Their choice of victims suggests a focus on industries that could pose significant risks to national security if compromised. The use of state-sponsored tactics indicates a likely intent to gather intelligence or execute disruptive activities.

Enhanced Description

TA410, also referred to as a state-sponsored actor, has demonstrated significant focus on the US utilities sector. In August 2019, Proofpoint identified TA410's activity through a campaign dubbed 'Lookback,' which used spear-phishing emails to target multiple US companies in the utilities sector. The phishing emails were crafted to appear as official communications from Global Energy Certification (GEC), leveraging the domain globalenergycertification.net. These emails contained malicious Microsoft Word documents with宏(hé) malware, designed to execute Lookback on compromised systems. TA410's ability to impersonate legitimate entities and remain undetected for extended periods highlights their sophistication in targeting critical infrastructure.

Key Capabilities

  • Spear-phishing campaigns using fake domains and legitimate-sounding emails
  • Delivery of malicious Microsoft Word documents with embedded macros
  • Deployment of Lookback malware for potential persistence or data theft
  • Ability to target critical infrastructure sectors
  • State-sponsored operational capabilities

MITRE ATT&CK Tactics

Espionage
Adversary Persistence

ATT&CK Techniques

T1566.001
T1486
T1042
T1059
T1078

Software / Tooling

Lookback malware
Malicious Microsoft Word documents with macros
Custom phishing domains

Campaigns & Victims

TA410's campaign in August 2019 demonstrated a persistent and targeted approach, indicating a possible long-term operational strategy. The use of a specific domain (globalenergycertification.net) to impersonate GEC suggests careful planning and a focus on credibility. This actor’s targeting patterns and techniques align with state-sponsored activity aiming to compromise critical infrastructure.

IOC Patterns

  • Spear-phishing emails originating from domains mimicking legitimate certification bodies
  • Malicious Microsoft Word attachments containing macros
  • Lookback malware detection
  • Email headers originating from .net domains

Recommended Actions

  • Enhance email filtering to detect and block spear-phishing attempts
  • Conduct employee training on identifying phishing emails
  • Monitor for malicious document downloads and macro activity
  • Implement network monitoring to detect Lookback malware indicators
  • Secure industrial control systems (ICS) against potentialattacks

Suggested Tags

APT
State-sponsored
Utilities sector targeting
Malware deployment
Critical infrastructure

Confidence Assessment

Moderate confidence in TA410's state-sponsored status and utility sector targeting due to specific campaign activities. Limited details on their long-term objectives, affiliations, and other campaigns outside 2019.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing
State-sponsored
Utilities sector targeting
Malware deployment
Critical infrastructure

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.