About this actor
In July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until now, nothing was known about who was responsible for this attack. Symantec researchers have discovered that this attack group, which we call Whitefly, has been operating since at least 2017, has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 15 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting.
Thin data: Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2016 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2016-0051 | 8.4 | 7.8 | 0.8028 | 2016-02-10 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1059Command and Scripting Interpreter ↗T1068Exploitation for Privilege Escalation ↗T1105Ingress Tool Transfer ↗T1204User Execution ↗T1204.002Malicious File ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-3 | 13 / 15 | 87% |
CM-2 | 12 / 15 | 80% |
CM-6 | 12 / 15 | 80% |
CM-7 | 12 / 15 | 80% |
SI-4 | 12 / 15 | 80% |
CA-7 | 10 / 15 | 67% |
SI-7 | 10 / 15 | 67% |
SI-2 | 8 / 15 | 53% |
AC-2 | 7 / 15 | 47% |
AC-3 | 7 / 15 | 47% |
AC-4 | 7 / 15 | 47% |
AC-6 | 7 / 15 | 47% |
SI-10 | 7 / 15 | 47% |
AC-5 | 4 / 15 | 27% |
CM-5 | 4 / 15 | 27% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- ShadowRay 0.35
- Triton Safety Instrumented System Attack 0.32
- PLATINUM 0.30
- Ferocious Kitten 0.30
- BackdoorDiplomacy 0.29