Uptime Hamster: 10d 12h 30mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Witchetty

Witchetty

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: LookingFrog, FlowingFrog, entre otros, objetivos estratégicos, FlowCloud, LookBack
Ver en IntelTracker → APTTrail →
Witchetty, also known as LookingFrog, is a cyber-espionage group first documented in April 2022, operating as a subgroup of the China-linked TA410 group, which is also referred to as APT10. The group's primary motivation is intelligence gathering, and it distinguishes itself through the consistent use of steganography to conceal malicious payloads within seemingly innocuous image files, such as Windows logos, a technique that allows them to host their implants on trusted platforms like GitHub. While often associated with the broader TA410 activities, Witchetty specifically focuses on refining its toolset and tactics to maintain a persistent presence in targeted networks for long-term data exfiltration.

Aliases del actor

LookingFrogFlowingFrogentre otrosobjetivos estratégicosFlowCloudLookBack

Actores similares

flowcloudactor · 1Container Orchestration Jobactor · 1LookBackapt · 0
Tecnicas MITRE
TA0040, TA0011, T1071, T1078, T1059.001, T1566
CVEs relacionadas
CVE-2020-0796
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
10
Actualizado
Wed, 08 No

Sectores objetivo (SOCRadar)

ManufacturingFinancePublic AdministrationInternet Publishing