U.S. Utilities Face Phishing Attacks Intent on Gaining Remote Access

Stu Sjouwerman | Aug 26, 2019

Last month saw a number of utility sector businesses targeted with spear phishing attacks that utilize a new remote access Trojan (RAT) that provides attackers with admin access.

We’ve seen a wave of attacks that appear to be focused on infrastructure-related organizations in the U.S. The recent seemingly coordinated attacks on local governments and municipalities are cause enough for alarm, but this latest string of attacks is downright frightening.

Last month, phishing emails targeting utilities appear to come from the US National Council of Examiners for Engineering and Surveying, utilizing a spoofed domain of NCEESS[dot]com. Using a scam involving exam “results notices”, the emails include a Word doc attachment that uses VBA macros to install a new RAT variant, dubbed LookBack.

Phishing%20email%20sample

 

LookBack is an impressive piece of code, with extended admin capabilities that allow an attacker to, discover the configuration of the infected endpoint, launch commands, establish a secure channel back to a command & control server, and more.

According to Bleeping Computer, the code used looks similar to attacks in 2018 targeting Japanese corporation. The utility sector attacks are suspected to be state-sponsored, possibly a Chinese espionage group.

Because phishing is the means of entry for these attacks, the good news is strong endpoint protection, DNS scanning can play a role in stopping the attacks before they reach the user’s inbox. Security Awareness Training can help educate users to spot suspicious emails (such as the use of a Word doc as the medium to provide exam results in the example above) and avoid clicking on the attachment in the first place.

 

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.