NEW: Group Profiler — instant APT intel lookup. Try it →

Whitefly

Overview

Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.

Naming & attribution

Whitefly is tracked under 1 names across the industry. It uses 9 documented ATT&CK techniques — more than 26% of the 174 groups tracked here. Activity attributed since at least 2017.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • BITTER — 5 shared techniques (25% overlap)
  • PLATINUM — 4 shared techniques (25% overlap)
  • Ferocious Kitten Iran — 3 shared techniques (25% overlap)
  • IndigoZebra China — 3 shared techniques (23% overlap)
  • APT19 China — 5 shared techniques (20% overlap)
  • BackdoorDiplomacy — 4 shared techniques (20% overlap)

TTPs — 9 techniques across 6 tactics

Resource Development

Privilege Escalation

Credential Access

Command and Control

Tools & malware (1)

Mimikatz

Reporting (1)