Proofpoint discovered the LookBack campaign when it came across some spear phishing emails purporting to be from the National Council of Examiners for Engineering and Surveying (NCEES) Each of these emails abused the NCEES logo, spoofed the sender address and reply-to fields. The emails used the pretense of a failed examination to trick employees at U.S. utility organizations into opening a Microsoft Word document named Result Notice.doc. This document leveraged VBA macros to install LookBack malware.”]

