Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Witchetty

Also known as: LookingFrog

Description

Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some links to the Cicada group (aka APT10). Witchetty’s activity was characterized by the use of two pieces of malware, a first-stage backdoor known as X4 and a second-stage payload known as LookBack. ESET reported that the group had targeted governments, diplomatic missions, charities, and industrial/manufacturing organizations.

AI Analysis

· 1 week ago

Executive Summary

Witchetty, also known as LookingFrog, is a sub-group of TA410 associated with Cicada (APT10) involved in cyber-espionage. They use X4 and LookBack malware targeting governments, diplomatic missions, charities, and industrial sectors globally. Their activities pose risks to sensitive data and require attention to advanced attack techniques.

Goals & Targeting

Witchetty likely aims to gather intelligence and steal sensitive data from targeted sectors, aligning with broader TA410 operations. Their victims include government agencies and industrial organizations, suggesting an intent to undermine national security and economic interests through espionage.

Enhanced Description

Witchetty emerged in April 2022 as part of TA410, linked to the Cicada group (APT10), engaging in cyber-espionage. Known for X4 and LookBack malware, they initially deploy X4 as a first-stage backdoor before delivering LookBack for data theft or espionage. Targeting includes governments, diplomatic entities, NGOs, and industrial sectors across multiple countries, indicating a strategic focus on sensitive information and critical infrastructure.

Key Capabilities

  • State-sponsored espionage activities
  • Two-stage malware deployment (X4 and LookBack)
  • Targeted attacks against critical infrastructure

MITRE ATT&CK Tactics

Espionage/Collections
Exfiltration

ATT&CK Techniques

T1566.003
T1082.001
T1070

Software / Tooling

X4 Backdoor
LookBack Malware

Campaigns & Victims

Witchetty's campaigns likely involve long-term, targeted operations for data collection. Their malware deployment suggests a patient approach to achieve persistence and stealth. Past activities include compromising diplomatic communications and industrial designs, necessitating robust defensive measures.

IOC Patterns

  • X4 backdoor signatures
  • LookBack payload hashes

Recommended Actions

  • Implement advanced email filtering
  • Monitor for unknown remote access tools
  • Enhance endpoint detection capabilities

Suggested Tags

APT
espionage
government

Confidence Assessment

Moderate confidence in known attributes, with gaps in specific TTPs and exact targeting locations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
government

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.