WitchettyWitchetty

Also known as: Witchetty · LookingFrog

Known aliases
2

Profile

Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some links to the Cicada group (aka APT10). Witchetty’s activity was characterized by the use of two pieces of malware, a first-stage backdoor known as X4 and a second-stage payload known as LookBack. ESET reported that the group had targeted governments, diplomatic missions, charities, and industrial/manufacturing organizations.

Aliases· 2

WitchettyLookingFrog

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
WIRTE
Actor
APT41
Actor
TA402
Group
EXOTIC LILY
Software
Winnti for Windows
Group
Wizard Spider
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.