Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Whitefly

Description

Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.(Citation: Symantec Whitefly March 2019)

Goals & Targeting

Targeted Sectors

Healthcare
Telecommunications
Media

AI Analysis

· 1 week ago

Executive Summary

Whitefly is a cyber espionage group targeting healthcare, telecommunications, and media sectors primarily in Singapore since 2017. Their primary motive is to steal sensitive information, as evidenced by their attack on SingHealth, Singapore's largest public health organization.

Goals & Targeting

Whitefly's primary objective is to steal sensitive information, particularly from healthcare institutions, although their targeting has expanded to include media and telecommunications sectors in Singapore. The group's focus on these industries suggests an interest in both personal data and potentially strategic information that could impact national security. Their victims are typically high-value targets with access to classified or proprietary information.

Enhanced Description

Whitefly operates as a sophisticated cyber espionage group with a focus on extracting sensitive data from targeted organizations. The group has predominantly targeted entities in Singapore across various sectors including healthcare, telecommunications, and media. Their activities have been linked to the breach of SingHealth, which resulted in one of the most significant healthcare cyber attacks in Singapore's history. Whitefly employs a variety of tactics, techniques, and procedures (TTPs) to achieve their objectives, including the use of malicious software and encrypted communication channels. The group's operations demonstrate a high level of planning and technical expertise, making them a notable threat to organizations handling sensitive information. Their targeting strategy appears to be driven by the goal of obtaining valuable intellectual property and strategic data.

Key Capabilities

  • Use of encrypted/encoded files
  • Spoofing legitimate resource names or locations
  • Malicious file creation
  • DLL injection techniques
  • Memory dumping attacks
  • Command and scripting interpreter usage
  • Ingress tool transfer

MITRE ATT&CK Tactics

Collection
Credential Access
Defense Evasion
Discovery
Exfiltration
Execution
Lateral Movement
Network
Reconnaissance
Subverting Governance

ATT&CK Techniques

T1027.013
T1036.005
T1204.002
T1574.001
T1003.001
T1059
T1588.002
T1068
T1105

Software / Tooling

Cobalt Strike
Custom Malware

Campaigns & Victims

Whitefly has been active since at least 2017, with notable operations including the SingHealth breach. Their campaigns frequently target high-profile organizations in Singapore's critical sectors, with a focus on data exfiltration. The group demonstrates advanced capabilities in persistence, lateral movement, and information theft.

IOC Patterns

  • Spear-phishing emails
  • Encrypted communication channels
  • Malicious scripts embedded in documents
  • Lateral movement across networks
  • C2 communication over HTTPS or DNS

Recommended Actions

  • Enhance network monitoring for encrypted and legitimate-looking traffic.
  • Implement strict patch management to mitigate known vulnerabilities.
  • Conduct regular user training on spear-phishing and social engineering tactics.
  • Monitor for unusual lateral movement indicators in network logs.
  • Encrypt sensitive data at rest and implement access controls.

Suggested Tags

APT
Espionage
Healthcare sector
Southeast Asia

Confidence Assessment

Whitefly's activities are well-documented due to high-profile incidents like the SingHealth attack. However, further details on their operational TTPs and targets outside Singapore would improve confidence in their threat profile.

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Symantec Whitefly March 2019 — Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.

Intel Summary

9

Techniques

5

Tools

1

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

APT
Espionage
Healthcare sector
Southeast Asia

Details

MITRE ID
G0107
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--b74f909f-8e52-4b69-b770-162bf59a1b4e
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.