>samit_hota
Back to adversary profiles

Threat Actor Dossier

The White Company (G0089): A State-Sponsored Espionage Threat

G0089

2 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
Unknown
Motivation
Espionage · Information Theft
Samit Hota·
Target Sectors
Government, Military
Associated Malware
Revenge RAT, NETWIRE
#threat-actor#g0089

Overview

The White Company, tracked by MITRE ATT&CK as G0089, is recognized as a sophisticated and likely state-sponsored threat actor. This group surfaced around 2017, quickly establishing a reputation for advanced capabilities in cyber espionage. Their primary objective appears to be information theft, targeting sensitive data from specific organizations. While a definitive country of origin remains officially unconfirmed, the sophistication of their operations and their focused targeting strongly suggest nation-state backing.

The group’s operational focus has historically been concentrated on government and military organizations within Pakistan, indicating a strategic interest in the geopolitical landscape of South Asia. Their campaigns are characterized by meticulous planning and a persistent approach to gain and maintain access to target networks. The White Company operates with a clear mandate for intelligence gathering, making them a significant concern for defense and governmental entities in their regions of interest.

Tactics & Techniques

The White Company employs a range of tactics, techniques, and procedures (TTPs) designed for initial access, execution, persistence, and defense evasion. A cornerstone of their initial access strategy involves spearphishing. They leverage carefully crafted phishing lure documents, often delivered as malicious Microsoft Word attachments, to trick unsuspecting users into compromising their systems. These documents are engineered to exploit known vulnerabilities, such as CVE-2012-0158 in Microsoft Word, to execute arbitrary code upon opening. This exploitation allows the group to establish a foothold within the target environment.

Once inside, The White Company demonstrates a clear understanding of stealth and system interaction. Their payloads are often obfuscated through software packing (T1027.002) to evade detection. They also incorporate capabilities such as file deletion (T1070.004) to remove traces of their activity, complicating incident response and forensic analysis. Furthermore, the group exhibits a degree of operational security by performing reconnaissance on victim systems, including checking for specific antivirus products like Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET (T1518.001). This allows them to adapt their approach or deployment based on the security posture of the compromised machine. They have also been observed employing system time discovery (T1124), checking the current date on victim systems, which might be used for timed operations or to bypass time-based security controls. These techniques collectively highlight a professional and adaptive adversary.

Notable Campaigns

The most prominent campaign attributed to The White Company is “Operation Shaheen.” This sophisticated espionage campaign ran from 2017 through 2018, primarily targeting government and military organizations within Pakistan. Security researchers, particularly Cylance, closely tracked and documented this operation, releasing findings in November 2018.

Operation Shaheen showcased The White Company’s advanced capabilities, including their ability to conduct extensive prior reconnaissance on their targets. The campaign involved the strategic deployment of malware to exfiltrate sensitive information, indicating a long-term, focused effort rather than opportunistic attacks. While specific details about the breadth of data compromised are not publicly exhaustive, the campaign’s duration and targets underscore its significance in the realm of state-sponsored cyber espionage. It serves as a definitive example of the group’s intent and technical proficiency.

Associated Malware & Tools

The White Company has been linked to the use of several distinct malware families and tools, which are central to their operational success. Two notable examples include:

  • Revenge RAT (S0379): This Remote Access Trojan (RAT) provides the threat actor with extensive control over compromised systems, enabling data exfiltration, execution of commands, and further reconnaissance. The use of a RAT indicates the group’s need for persistent, flexible access to victim environments.
  • NETWIRE (S0198): Also a RAT, NETWIRE is known for its information-gathering capabilities and its ability to bypass certain security measures. Its inclusion in The White Company’s toolkit further emphasizes their focus on espionage and data theft.

The selection of these tools suggests a preference for robust and versatile malware that can facilitate various stages of their attack lifecycle, from maintaining persistence to executing data collection and exfiltration activities.

Current Status

As of recent observations, The White Company (G0089) continues to be recognized as a relevant threat actor within the cybersecurity landscape. While specific active campaigns beyond 2018 are not explicitly detailed in publicly available summaries, the MITRE ATT&CK profile for G0089 was last modified in April 2025. This maintenance and update of their profile by a leading authority in threat intelligence indicates that the group is not considered dormant or disbanded. It suggests that The White Company remains a persistent entity with potential for future operations, or that its past activities and associated TTPs are still considered relevant for defensive planning. Security professionals should continue to monitor intelligence regarding this group, particularly given its state-sponsored nature and advanced capabilities.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call