The White Company is a likely state-sponsored APT group primarily targeting government and military organizations in Pakistan.
Analyst brief
The White Company is a likely state-sponsored threat actor with advanced capabilities. It primarily targets government and military organizations in Pakistan. The group leverages spearphishing attachments for initial access, followed by execution via malicious files dropping Revenge RAT and NETWIRE, while employing stealth techniques like software packing and file deletion. Defenders should focus on detecting suspicious email attachments, monitoring for security software discovery attempts, and investigating unusual system time queries.
The White Company
unknown
The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.