ATT&CKGroupsWhitefly

Whitefly

G0107

Threat group.View on attack.mitre.org

About this group

Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1003.001
LSASS Memory

Whitefly has used Mimikatz to obtain credentials.

T1027.013
Encrypted/Encoded File

Whitefly has encrypted the payload used for C2.

T1036.005
Match Legitimate Resource Name or Location

Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors.

T1059
Command and Scripting Interpreter

Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.

T1068
Exploitation for Privilege Escalation

Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.

T1105
Ingress Tool Transfer

Whitefly has the ability to download additional tools from the C2.

T1204.002
Malicious File

Whitefly has used malicious .exe or .dll files disguised as documents or images.

T1574.001
DLL

Whitefly has used search order hijacking to run the loader Vcrodat.

T1588.002
Tool

Whitefly has obtained and used tools such as Mimikatz.

Software1

Campaigns0

None recorded.

References1

  1. Symantec Whitefly March 2019 Open source
    Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.