Whitefly is a cyber espionage threat actor associated with long-term intrusions and stealthy post-compromise activity. The group has been linked to operations targeting organizations in Singapore. Whitefly is known for using modular malware and remote access tooling that can download additional payloads from command-and-control infrastructure, enabling multi-stage intrusions and flexible post-exploitation. Operationally, Whitefly has used malicious executable and DLL payloads disguised as benign documents or images to induce execution and reduce suspicion. The group has also employed masquerading by naming malicious DLLs after components associated with legitimate security software vendors. Whitefly has demonstrated use of DLL search order hijacking and related side-loading behavior, including use of a loader referred to as Vcrodat, to execute malicious code through trusted application workflows. Reported tradecraft also includes simple remote shell capability for interactive command execution after compromise. Observed ATT&CK-aligned behaviors attributed to Whitefly include command and scripting interpreter use, exploitation for privilege escalation, and path interception through PATH environment variable abuse. The group’s emphasis on stealth, staged tooling, and covert persistence is consistent with an intelligence-gathering mission rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
This analytic detects Windchill MethodServer log4j events that contain the CVE-2026-4681 exploitation probe run?c=echo%20GW_READY_OK . PTC identifies GW_READY_OK and related run?c= activity as log indicators associated with Windchill and FlexPLM exploitation.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as an annotated threat actor associated with this generic Linux shared-memory execution detection.
Mentioned only as an annotation/tag associated with a privilege escalation detection.
Mentioned only as an annotated threat actor associated with the detection content; no campaign or activity by the group is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.