Witchetty
Aliases: LookingFrog
- First seen
- 2022-04-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:06:02
Targeted industries: government-and-public-sector education-and-nonprofits manufacturing
Context
Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some links to the Cicada group (aka APT10). Witchetty’s activity was characterized by the use of two pieces of malware, a first-stage backdoor known as X4 and a second-stage payload known as LookBack. ESET reported that the group had targeted governments, diplomatic missions, charities, and industrial/manufacturing organizations.
Reports & references
- rewterz.com — Rewterz Threat Alert Witchetty Apt Group Active Iocs (report)
- Broadcom/Symantec — Witchetty Steganography Espionage (report)
- ESET — Lookback Ta410 Umbrella Cyberespionage Ttps Activity (report)