Whitefly
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Whitefly is an alias used for a threat actor that has been publicly linked to Singapore. According to a Symantec report cited in Reuters, the group has been operating since at least 2017 and is described by the researchers as a small- to medium-sized team. The same assessment labels Whitefly as a state-sponsored espionage group, although the exact sponsoring state is not identified in the public sources.
The actor’s known focus is confined to organizations located within Singapore. Symantec observed that Whitefly repeatedly targeted sectors such as healthcare, media, telecommunications and engineering. The strategic objective described in the reporting is espionage, with the group seeking to acquire large volumes of sensitive information rather than pursuing financial gain or disruptive outcomes.
One of the most prominent campaigns attributed to Whitefly involved the compromise of a Singaporean health database. Between May 2015 and July 2018, the attackers accessed and copied the non‑medical personal details of roughly 1.5 million individuals, including the prime minister and other senior officials. Symantec characterized this breach as part of a wider pattern of intrusions rather than an isolated incident.
Attribution to Whitefly rests primarily on the Symantec analysis that linked the tactics, targets and persistent focus on Singaporean entities to a single actor. The report explicitly states that the group is state‑sponsored, but it does not name the sponsoring government or associate the actor with any criminal consortium. No public indictments or legal designations have been released that further clarify the group’s affiliation.
Publicly available descriptions of Whitefly’s tradecraft are limited to the outcome of the attacks—data exfiltration from government‑linked databases. The sources do not specify particular malware families, initial‑access vectors or custom tooling employed by the group. Consequently, the profile can only note that the actor’s methodology resulted in the large‑scale theft of personal information, without detailing the specific technical means used to achieve that result.
Incidents
Attributed incidents are available to members.
1 incident