Cyber Resilience

Threat actor · all actors

WhiteflyG0107 unknown

aka Whitefly

Last updated: 2026-08-20

1attributed CVEs
15ATT&CK techniques
4.3IDF score (tooling uniqueness)
1exclusive CVEs
2016years active

About this actor

In July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until now, nothing was known about who was responsible for this attack. Symantec researchers have discovered that this attack group, which we call Whitefly, has been operating since at least 2017, has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0107

Unclassifiedno scheme matched

Whitefly

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 15 ATT&CK techniques on file.
Named victims
1 extracted from reporting.

Thin data: Only one named victim is on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2016-0051 8.47.80.80282016-02-10see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-313 / 1587%
CM-212 / 1580%
CM-612 / 1580%
CM-712 / 1580%
SI-412 / 1580%
CA-710 / 1567%
SI-710 / 1567%
SI-28 / 1553%
AC-27 / 1547%
AC-37 / 1547%
AC-47 / 1547%
AC-67 / 1547%
SI-107 / 1547%
AC-54 / 1527%
CM-54 / 1527%

Co-occurring actors

None.

Similar actors

Active in same years