Whitefly

MITRE ATT&CK: G0107 View on attack.mitre.org

Aliases: Whitefly

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:56:48

Targeted industries: healthcare-and-pharmaceutical government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:sg

Context

Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.

Detection coverage

  • 7 YARA rules
  • 362 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • DLL (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Tool (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Malicious File (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Mimikatz (malware)

Reports & references

  • Broadcom/Symantec — Whitefly Espionage Singapore (report)
  • reuters.com — Cyberattack On Singapore Health Database Steals Details Of 1 5 Million Including Pm Iduskbn1Ka14J (report)
  • MITRE ATT&CK — G0107 (report)
  • Broadcom/Symantec — Whitefly Espionage Singapore (report)

External references