The White Company
MITRE ATT&CK: G0089 View on attack.mitre.org
Aliases: The White Company
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:30:10
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:pk
Context
The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.
Detection coverage
- 89 Sigma rules
Malware & tools used
- Software Packing (attack-pattern)
- Security Software Discovery (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- File Deletion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Malicious File (attack-pattern)
- System Time Discovery (attack-pattern)
- NETWIRE (malware)
- Revenge RAT (malware)
Reports & references
- MITRE ATT&CK — G0089 (report)
- cylance.com — Whitecompanyoperationshaheenreport (report)