>samit_hota
Back to adversary profiles

Threat Actor Dossier

Whitefly (G0107) Threat Profile: Singapore's Persistent Cyber Espionage Adversary

G0107

10 sectors targeted

Threat level
HIGH
Status
UNKNOWN
Origin
China
Motivation
Espionage · Information Theft
Samit Hota·
Target Sectors
Healthcare, Media, Telecommunications, Engineering, Government, Critical Infrastructure, Automotive, Defense, Military, Weapon Industries
Associated Malware
Vcrodat, Mimikatz, Termite, Nibatad, ShimRAT, Simple Remote Shell Tool, Multipurpose Command Tool
#threat-actor#g0107

Overview

Whitefly, tracked by MITRE ATT&CK as G0107, is a cyber espionage group that has been actively operating since at least 2017. This sophisticated threat actor is primarily driven by the objective of stealing large volumes of sensitive information, positioning them as a state-sponsored entity focused on intelligence gathering rather than financial gain. While initial reports by Symantec in 2019 identified Whitefly as a distinct group primarily targeting entities within Singapore, some threat intelligence researchers consider Whitefly to be closely related to, or an alias for, a broader threat actor known as Mofang (MITRE G0103). This connection suggests a likely origin in China, with Mofang specifically attributed to operating out of the country and being government-affiliated.

The group’s operational focus has predominantly been on organizations based in Singapore, including multinational corporations with a significant presence in the city-state. Whitefly has demonstrated a wide-ranging interest across various sectors, notably healthcare, media, telecommunications, and engineering. If the broader linkage to Mofang holds, their targeting scope extends even further to include government, military, critical infrastructure, and the automotive and weapon industries across a wider geographic area that encompasses Canada, Germany, India, Myanmar, South Korea, and the USA, in addition to Singapore, Russia, and the United Kingdom. This indicates a persistent and adaptable adversary capable of executing long-term espionage campaigns.

Tactics & Techniques

Whitefly employs a combination of custom malware, publicly available hacking tools, and “living off the land” techniques to achieve its objectives and maintain a stealthy presence within victim networks. Their attack chain typically begins with spear-phishing campaigns. Initial compromise often involves malicious executable (.exe) or dynamic-link library (.dll) files, which are carefully disguised as legitimate documents or images. These lures are frequently themed around job openings or other industry-relevant content, increasing the likelihood of an unsuspecting user executing them.

Once executed, the dropper deploys a custom loader known as Trojan.Vcrodat. A key technique consistently used by Whitefly to launch Vcrodat is search order hijacking, also referred to as DLL load-order attacks. This method exploits the predictable order in which Windows searches for DLLs, allowing the attackers to place a malicious DLL in a location that will be loaded before the legitimate one. Vcrodat then proceeds to decrypt and load additional malicious payloads directly into memory, establishes communication with command-and-control (C2) servers, transmits system information from the infected host, and downloads further tools. To enhance resilience, Whitefly is known to configure multiple C2 domains for each target.

Following initial access, the group focuses on network mapping and lateral movement to expand their foothold within the compromised environment. They are known for their patience and persistence, often maintaining access to targeted organizations for extended periods—sometimes months—to facilitate the exfiltration of large volumes of sensitive data. Whitefly leverages legitimate system utilities like PowerShell and other open-source penetration testing tools, a tactic known as “living off the land,” to blend their malicious activities with normal network traffic and evade detection. They also exploit known vulnerabilities, such as the Windows privilege escalation vulnerability CVE-2016-0051, on unpatched systems. Other techniques include naming malicious DLLs to mimic legitimate security software and encrypting C2 payloads to avoid analysis.

Notable Campaigns

The most widely reported and significant incident attributed to Whitefly (G0107) is the cyberattack against SingHealth, Singapore’s largest public health organization, in July 2018. This breach, considered Singapore’s most serious personal data compromise, resulted in the theft of personal information and medication details belonging to 1.5 million patients, including the Prime Minister.

The SingHealth attack was not an isolated incident but part of a broader series of targeted operations by Whitefly against various Singapore-based organizations between mid-2017 and mid-2018. Symantec’s 2019 report revealed that Whitefly targeted less than ten organizations in Singapore across the healthcare, media, telecommunications, and engineering sectors during this period. While most direct evidence of Whitefly’s activities centers on Singapore, some of the tools identified in their operations have also been observed in attacks outside Singapore, against defense, telecommunications, and energy entities in Southeast Asia, Russia, and the United Kingdom. One instance of their custom malware, Vcrodat, was also reported in an attack against a UK-based hospitality organization.

Associated Malware & Tools

Whitefly maintains a versatile toolkit comprising both custom-developed malware and readily available open-source tools to execute its operations:

  • Vcrodat: This is Whitefly’s primary custom loader and backdoor, consistently used in their campaigns. It is responsible for decrypting and loading subsequent payloads, establishing C2 communications, and downloading additional tools.
  • Simple Remote Shell Tool: A basic remote shell utility employed for maintaining C2 communication and executing commands on compromised systems.
  • Multipurpose Command Tool: In some attacks, Whitefly has utilized a versatile command tool that supports a range of post-compromise activities.
  • Mimikatz (Hacktool.Mimikatz): A widely known open-source post-exploitation tool primarily used by Whitefly to extract credentials from memory, facilitating lateral movement and privilege escalation within victim networks.
  • Termite (Hacktool.Termite): Identified as an open-source hacking tool, potentially a rootkit, used for more complex actions like controlling multiple compromised machines.
  • CVE-2016-0051 Exploit Tool: Whitefly has leveraged an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched systems, allowing them to gain elevated privileges.
  • Living off the Land Tools: The group frequently abuses legitimate system tools such as PowerShell scripts to carry out malicious activities without introducing new, potentially detectable, malware.
  • Nibatad & ShimRAT: These are additional malware families or tools that have been associated with Mofang, the broader group with which Whitefly is sometimes linked. If the connection between Whitefly and Mofang is indeed accurate, these tools would also fall under their operational capabilities.

Current Status

As of mid-2026, publicly reported information regarding new and specific campaigns or incidents directly attributed to Whitefly (G0107) largely concludes with the comprehensive reporting from Symantec in March 2019, which detailed activities up to late 2018. While the MITRE ATT&CK entry for Whitefly (G0107) was last updated in May 2020, and platforms like Tidal Cyber reflect updates as recent as April 2022, these updates primarily summarize previously disclosed information rather than detailing new operational activities.

The absence of recent public reporting on specific Whitefly operations does not necessarily indicate a cessation of activity. State-sponsored cyber espionage groups like Whitefly often operate with a high degree of stealth, and their activities can remain undetected or unpublicized for extended periods. Given their established capabilities, persistence, and the strategic importance of their historical targets, it is plausible that Whitefly remains an active threat, continuing its intelligence-gathering mission without recent public disclosure. However, based solely on publicly available threat intelligence, their current operational status beyond 2022 remains unknown. Organizations, particularly those in critical sectors in Singapore and Southeast Asia, should continue to maintain vigilance against the tactics and tools historically associated with this group.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call