Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors The White Company

Description

The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.(Citation: Cylance Shaheen Nov 2018)

AI Analysis

· 1 week ago

Executive Summary

The White Company is a state-sponsored threat actor with advanced capabilities known for conducting espionage campaigns. They primarily target government and military organizations, focusing on intelligence gathering. Their activities have been linked to Operation Shaheen, which occurred between 2017 and 2018, indicating a persistent and targeted approach.

Goals & Targeting

The White Company's strategic objectives appear to align with those of a state-sponsored actor, likely aiming to gather intelligence for geopolitical or military purposes. They specifically target government and military organizations, suggesting a focus on espionage rather than financial gain or disruption. The targeting of Pakistan during Operation Shaheen indicates a focus on South Asian geopolitical interests.

Enhanced Description

The White Company is suspected to be a state-sponsored threat actor with advanced capabilities. They are known for conducting espionage campaigns, including Operation Shaheen, which targeted government and military organizations in Pakistan between 2017 and 2018. The group's operations demonstrate sophistication, utilizing tools such as NETWIRE and Revenge RAT. Their primary focus appears to be on intelligence gathering and compromising sensitive information from their targets.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Use of custom malware (NETWIRE, Revenge RAT)
  • Spear-phishing with malicious attachments
  • Exploitation of system vulnerabilities

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1204.002: Malicious File
T1203: Exploitation for Client Execution
T1518.001: Security Software Discovery
T1070.004: File Deletion
T1027.002: Software Packing
T1124: System Time Discovery
T1566.001: Spearphishing Attachment

Software / Tooling

NETWIRE
Revenge RAT
Cobalt Strike (inferred from similar TTPs)
Mimikatz (similar tools)

Campaigns & Victims

The White Company is known for Operation Shaheen, a targeted espionage campaign against Pakistani government and military entities. The group demonstrates persistence, with activity spanning at least two years. Their use of sophisticated malware suggests a high level of resource and development investment. Notable patterns include the use of spear-phishing attachments and malicious files to compromise targets.

IOC Patterns

  • Spear-phishing emails with malicious Office document attachments
  • Malicious file downloads from compromised websites
  • Network activity indicative of C2 communication (e.g., unusual DNS queries)
  • Signs of malware installation, including dropped files and registry modifications

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts.
  • Monitor for unusual network traffic patterns, particularly related to known C2 infrastructure.
  • Use endpoint detection and response (EDR) solutions to identify malicious file activity.
  • Conduct regular vulnerability assessments on critical systems to mitigate exploitation risks.
  • Educate employees about phishing tactics and implement training programs.

Suggested Tags

State-sponsored
Espionage
Advanced Persistent Threat
Government targeting

Confidence Assessment

Confidence in the assessment of The White Company is high, based on their clear association with Operation Shaheen and linked TTPs. However, gaps exist regarding their exact state sponsorship and specific tactics beyond those observed in available intelligence.

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Cylance Shaheen Nov 2018 — Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

Intel Summary

7

Techniques

2

Tools

1

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

APT
Government Targeting
State-sponsored
Espionage
Advanced Persistent Threat
Government targeting

Details

MITRE ID
G0089
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6688d679-ccdb-4f12-abf6-c7545dd767a4
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.