LookBack
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: FlowCloud, LookingFrog, Witchetty
LookBack is a Remote Access Trojan (RAT) that first emerged in July 2019, primarily observed in cyber espionage campaigns targeting critical infrastructure in the United States. It is assessed with high confidence to be of Chinese origin, deployed by state-sponsored threat actors whose primary motivation is data exfiltration and gaining remote control for espionage purposes. What sets LookBack apart is its use of a proxy mechanism for command and control (C2) communication, designed to evade detection. While some artifacts linked it to APT10 activity in 2018, public reporting clarifies that the LookBack malware itself has not been formally attributed to a specific known APT actor, nor are there validated aliases for the malware itself.