The White Company
Overview
The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.
Naming & attribution
The White Company is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Elderwood China — 4 shared techniques (33% overlap)
- APT12 China — 3 shared techniques (33% overlap)
- TA459 China — 3 shared techniques (33% overlap)
- Aoqin Dragon China — 3 shared techniques (23% overlap)
- Darkhotel South Korea — 5 shared techniques (19% overlap)
- Saint Bear Russia — 4 shared techniques (19% overlap)
Malware families with current indicators
2 families attributed to The White Company, carrying 502 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- RevengeRAT 251 indicators
- NetWire 251 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 7 techniques across 4 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1203Exploitation for Client Execution -
T1204.002Malicious File
Stealth
-
T1027.002Software Packing -
T1070.004File Deletion
Discovery
-
T1124System Time Discovery -
T1518.001Security Software Discovery
Tools & malware (2)
Revenge RAT · NETWIRE
Reporting (1)
- Operation Shaheen — Livelli, K, et al