{"id":10977,"date":"2019-08-01T00:00:00","date_gmt":"2019-08-01T00:00:00","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/targeting-of-u-s-utility-companies\/"},"modified":"2019-08-01T00:00:00","modified_gmt":"2019-08-01T00:00:00","slug":"targeting-of-u-s-utility-companies","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/targeting-of-u-s-utility-companies","title":{"rendered":"Targeting of U.S. utility companies"},"content":{"rendered":"<p>Between July 19 and July 25, 2019, a threat actor sent several spear-phishing emails to three U.S. companies in the utility sector. The emails were sent from a domain impersonating that of the National Council of Examiners for Engineering and Surveying, an authority in the industry. The emails contained Microsoft Word attachments that used macros to install and run a new remote-access Trojan (RAT) called LookBack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Between July 19 and July 25, 2019, a threat actor sent several spear-phishing emails to three U.S. companies in the utility sector. The emails were sent from a domain impersonating that of the National Council of Examiners for Engineering and Surveying, an authority in the industry. The emails contained Microsoft Word attachments that used macros [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"cyber_operation":[49],"state_sponsor":[],"victim_category":[138],"victim_government_response":[],"victim":[182],"class_list":["post-10977","post","type-post","status-publish","format-standard","hentry","category-incident","cyber_operation-espionage","victim_category-private-sector","victim-united-states"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10977"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10977\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10977"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10977"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10977"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10977"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10977"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}