Witchetty is a cyber-espionage subgroup under TA410 known for using X4 and LookBack malware.
Analyst brief
Witchetty (also known as LookingFrog) is a cyber-espionage subgroup operating under the TA410 umbrella and linked to the Cicada group (APT10). The group primarily targets governments, diplomatic missions, charities, and industrial/manufacturing organizations. Their main TTPs involve the use of a first-stage backdoor called X4 and a second-stage payload named LookBack. Defenders should focus on indicators related to X4 and LookBack malware, as well as internal lateral movement and C2 communications.
Witchetty
LookingFrog
unknown
Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some links to the Cicada group (aka APT10). Witchetty’s activity was characterized by the use of two pieces of malware, a first-stage backdoor known as X4 and a second-stage payload known as LookBack. ESET reported that the group had targeted governments, diplomatic missions, charities, and industrial/manufacturing organizations.