White Company
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The White Company, also known by its alias, is a threat actor that has been linked to China-based operations. Public reporting describes it as a nation‑state actor engaged in state‑sponsored cyberespionage. The group’s known activities focus on military and government targets, with the Pakistan Air Force serving as a primary example of its targeting. Its strategic objective, as evidenced by the Operation Shaheen campaign, is the collection of tactical and strategic intelligence rather than financial gain or disruption.
In that campaign, the White Company employed spear‑phishing messages that contained weaponized lure files referencing topics of interest to the Pakistani Air Force, such as government affairs and Chinese military advisers. Initial access was achieved either through links to compromised websites or via malicious Word document attachments delivered in the phishing emails. The malware used in the operation incorporated multiple packing—specifically five layers—to conceal the final payload and evade detection by major antivirus products. Researchers noted that the threat actor combined tools created by several different developers, some of whom had taken steps to obscure their own contributions, in an effort to whitewash the attack’s origins. The group’s tooling style reflects a reliance on zero‑day exploits and exploit developers.
Attribution of the White Company to a specific state remains uncertain in public sources, although it is consistently characterized as a nation‑state actor with state sponsorship. The Operation Shaheen incident, reported in November 2018, stands as the most detailed publicly disclosed operation attributed to this actor. No other campaigns are described in the available material, so the profile is limited to the facts presented in the Operation Shaheen reporting.
Incidents
Attributed incidents are available to members.
1 incident