Witchetty, also known as LookingFrog, is a cyber-espionage group first documented in April 2022, operating as a subgroup of the China-linked TA410 group, which is also referred to as APT10. The group's primary motivation is intelligence gathering, and it distinguishes itself through the consistent use of steganography to conceal malicious payloads within seemingly innocuous image files, such as Windows logos, a technique that allows them to host their implants on trusted platforms like GitHub. While often associated with the broader TA410 activities, Witchetty specifically focuses on refining its toolset and tactics to maintain a persistent presence in targeted networks for long-term data exfiltration.