Witchetty

Aliases: LookingFrog

First seen
2022-04-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:06:02

Targeted industries: government-and-public-sector education-and-nonprofits manufacturing

Context

Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some links to the Cicada group (aka APT10). Witchetty’s activity was characterized by the use of two pieces of malware, a first-stage backdoor known as X4 and a second-stage payload known as LookBack. ESET reported that the group had targeted governments, diplomatic missions, charities, and industrial/manufacturing organizations.

Reports & references

  • rewterz.com — Rewterz Threat Alert Witchetty Apt Group Active Iocs (report)
  • Broadcom/Symantec — Witchetty Steganography Espionage (report)
  • ESET — Lookback Ta410 Umbrella Cyberespionage Ttps Activity (report)

External references