Whitefly is a cyber threat actor tracked in open reporting as an intrusion set associated with long-term espionage activity. The group has been linked to operations targeting organizations in Asia, including entities in sectors such as telecommunications, media, engineering, and government-related environments. Whitefly is generally characterized as a stealth-focused operator that emphasizes persistence, credential access, remote administration, and defense evasion over disruptive or destructive effects. Observed tradecraft includes delivery and use of malicious executable and dynamic-link library payloads disguised as benign documents or images, as well as masquerading of malicious components with names resembling legitimate software files, including software associated with security vendors. Whitefly has used encrypted payloads and command-and-control traffic to hinder detection and analysis. The group has also deployed simple remote shell capabilities that beacon to command-and-control infrastructure and await operator tasking, enabling interactive post-compromise control. For credential access and post-exploitation, Whitefly has obtained and used publicly available offensive tooling such as Mimikatz. Reported behavior also aligns with common privilege-escalation and persistence techniques, including exploitation for privilege escalation and abuse of Windows services for persistence or installation. Additional ATT&CK mappings associated with Whitefly in available reporting include command and scripting interpreter use, setuid and setgid abuse in Linux contexts, and escape-to-host behavior in network or appliance-oriented environments. Whitefly appears in reporting under the alias Whitefly. High-confidence public information on formal sub-groups, definitive malware family ownership, or a conclusively attributed sponsoring state remains limited in the provided material, so those points cannot be stated with certainty.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
This analytic detects Windchill MethodServer log4j events that contain the CVE-2026-4681 exploitation probe run?c=echo%20GW_READY_OK . PTC identifies GW_READY_OK and related run?c= activity as log indicators associated with Windchill and FlexPLM exploitation.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed in the detection annotations as a threat actor associated with this analytic context.
Referenced in the detection annotations as a threat actor associated with exploitation for privilege escalation activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.