Whitefly is a cyber threat actor known for stealing 1.5 million patient records from SingHealth in 2018.
Analyst brief
Whitefly is a cyber threat actor active since at least 2017, known for targeting organizations primarily in Singapore across multiple sectors, most notably breaching SingHealth in 2018 to steal 1.5 million patient records. Their key TTPs include using Mimikatz to dump credentials from LSASS memory (T1003.001), deploying malicious files for execution (T1204.002), and using DLL side-loading (T1574.001) for stealth and persistence. Defenders should focus on monitoring and hardening LSASS access, detecting Mimikatz tool transfers via ingress monitoring (T1105), and implementing strict controls on script execution and privilege escalation exploits (T1068).
Whitefly
unknown
In July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until now, nothing was known about who was responsible for this attack. Symantec researchers have discovered that this attack group, which we call Whitefly, has been operating since at least 2017, has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information.