ATT&CKReferencesSymantec Whitefly March 2019

Symantec Whitefly March 2019

Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupWhitefly

Whitefly has used Mimikatz to obtain credentials.

T1027.013
Encrypted/Encoded File
GroupWhitefly

Whitefly has encrypted the payload used for C2.

T1036.005
Match Legitimate Resource Name or Location
GroupWhitefly

Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors.

T1059
Command and Scripting Interpreter
GroupWhitefly

Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.

T1068
Exploitation for Privilege Escalation
GroupWhitefly

Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.

T1105
Ingress Tool Transfer
GroupWhitefly

Whitefly has the ability to download additional tools from the C2.

T1204.002
Malicious File
GroupWhitefly

Whitefly has used malicious .exe or .dll files disguised as documents or images.

T1574.001
DLL
GroupWhitefly

Whitefly has used search order hijacking to run the loader Vcrodat.

T1588.002
Tool
GroupWhitefly

Whitefly has obtained and used tools such as Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.