NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the The White Company threat group

The White Company

Overview

The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.

Naming & attribution

It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Elderwood China — 4 shared techniques (33% overlap)
  • APT12 China — 3 shared techniques (33% overlap)
  • TA459 China — 3 shared techniques (33% overlap)
  • Aoqin Dragon China — 3 shared techniques (23% overlap)
  • Darkhotel South Korea — 5 shared techniques (19% overlap)
  • Saint Bear Russia — 4 shared techniques (19% overlap)

Malware families with tracked indicators

2 families attributed to The White Company, with 12 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • RevengeRAT 6 indicators
  • NetWire 6 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 7 techniques across 4 tactics

Initial Access

Stealth

Tools & malware (2)

Revenge RAT · NETWIRE

Reporting (1)