Intrusion setG0107
Whitefly
Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.
- Documented techniques
- 9
- Assessed motivation
- Espionage
- First seen
- 2017
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development1
privilege escalation1
credential access1
command and control1
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.
Mimikatz