The White Company

MITRE ATT&CK: G0089 View on attack.mitre.org

Aliases: The White Company

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:30:10

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:pk

Context

The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.

Detection coverage

  • 89 Sigma rules

Malware & tools used

  • Software Packing (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • File Deletion (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious File (attack-pattern)
  • System Time Discovery (attack-pattern)
  • NETWIRE (malware)
  • Revenge RAT (malware)

Reports & references

  • MITRE ATT&CK — G0089 (report)
  • cylance.com — Whitecompanyoperationshaheenreport (report)

External references