ETDA ThaiCERT
Report
Search
Home > List all groups > The White Company

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link APT group: The White Company

NamesThe White Company (Cylance)
Country[Unknown]
SponsorState-sponsored
MotivationInformation theft and espionage
First seen2017
Description(Cylance) Cylance has determined that Operation Shaheen was an espionage campaign executed over the course of the last year. It was a targeted campaign which appeared to focus on individuals and organizations in Pakistan, specifically the government and the military. Cylance’s window into this campaign, though significant, is not all-encompassing. Indeed, our research revealed evidence that The White Company conducted extensive prior reconnaissance of its targets, and continues to operate largely unnoticed by the security community.
ObservedSectors: Defense, Government.
Countries: Pakistan.
Tools used
Operations performedNov 2017Operation “Shaheen”
We have dubbed the first campaign Operation Shaheen. It examines a complex espionage effort directed at the Pakistani military.
Information<https://www.cylance.com/content/dam/cylance-web/en-us/resources/knowledge-center/resource-library/reports/WhiteCompanyOperationShaheenReport.pdf>
MITRE ATT&CK<https://attack.mitre.org/groups/G0089/>

Last change to this card: 22 April 2020

Download this actor card in PDF or JSON format

Previous: Wassonite
Next: Whitefly, Mofang

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key