Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors White Company

Description

**Targets:** Pakistani government and military — in particular, the Pakistani Air Force **Operations:** Shaheen

Goals & Targeting

Targeted Sectors

Government
Defense

AI Analysis

· 1 week ago

Executive Summary

White Company is a nation-state threat actor primarily engaged in espionage activities targeting military and defense sectors, particularly focusing on Pakistan's Air Force as part of their campaign known as Operation Shaheen.

Goals & Targeting

White Company targets government and defense sectors, particularly focusing on Pakistan's Air Force. The targeting pattern indicates a strategic focus on military communications and classified data, likely aiming to gather intelligence that could provide a competitive advantage or disrupt national security operations.

Enhanced Description

White Company operates with the primary motivation of conducting espionage, targeting government and defense sectors. Their operations, such as Operation Shaheen, suggest a focus on gathering strategic intelligence that could be valuable to national security interests. The actor employs tactics typically associated with nation-state adversaries, including long-term data collection and exfiltration strategies to avoid detection. White Company's activities highlight the need for robust cybersecurity measures in military and defense infrastructure to protect sensitive information from targeted espionage campaigns.

Key Capabilities

  • Military-grade cyber espionage tools
  • Targeted phishing campaigns
  • Data exfiltration techniques
  • Social engineering tactics

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1059.003
T1048
T1077
T1215

Software / Tooling

Custom malware frameworks
Command and Control (C2) communication tools
Credential harvesting tools

Campaigns & Victims

White Company is known for Operation Shaheen, which targets the Pakistani government and military. The campaign likely involves long-term observation to gather critical intelligence without immediate detection. The actor's focus on military and defense sectors suggests a strategic, perhaps state-aligned objective.

IOC Patterns

  • Spear-phishing emails targeting military personnel
  • C2 communication using encrypted channels
  • Network reconnaissance activities before data exfiltration
  • Use of domain generation algorithms for persistence

Recommended Actions

  • Implement strict network monitoring and threat detection systems.
  • Secure supply chains to prevent compromises in software updates.
  • Conduct regular penetration testing focusing on military infrastructure.
  • Enforce multi-factor authentication (MFA) on sensitive accounts.
  • Educate employees about phishing threats and social engineering tactics.

Suggested Tags

APT
Nation-state
Espionage
Defense sector

Confidence Assessment

This report is based on limited available data. While the threat actor's primary motivation and targeting sectors are clear, specific technical capabilities, associated tools, and exact attack patterns remain uncertain. Further intelligence gathering would improve confidence in these findings.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
Nation-state
Espionage
Defense sector

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.