Whitefly
MITRE ATT&CK: G0107 View on attack.mitre.org
Aliases: Whitefly
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:56:48
Targeted industries: healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:sg
Context
Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.
Detection coverage
- 7 YARA rules
- 362 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- DLL (attack-pattern)
- LSASS Memory (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Tool (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Malicious File (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Mimikatz (malware)
Reports & references
- Broadcom/Symantec — Whitefly Espionage Singapore (report)
- reuters.com — Cyberattack On Singapore Health Database Steals Details Of 1 5 Million Including Pm Iduskbn1Ka14J (report)
- MITRE ATT&CK — G0107 (report)
- Broadcom/Symantec — Whitefly Espionage Singapore (report)