Threat group.View on attack.mitre.org
Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
|
| T1027.013 Encrypted/Encoded File |
Whitefly has encrypted the payload used for C2. |
| T1036.005 Match Legitimate Resource Name or Location |
Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors. |
| T1059 Command and Scripting Interpreter |
Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands. |
| T1068 Exploitation for Privilege Escalation |
Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers. |
| T1105 Ingress Tool Transfer |
Whitefly has the ability to download additional tools from the C2. |
| T1204.002 Malicious File |
Whitefly has used malicious .exe or .dll files disguised as documents or images. |
| T1574.001 DLL |
Whitefly has used search order hijacking to run the loader Vcrodat. |
| T1588.002 Tool |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.