ATT&CKGroupsThe White Company

The White Company

G0089

Threat group.View on attack.mitre.org

About this group

The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.002
Software Packing

The White Company has obfuscated their payloads through packing.

T1070.004
File Deletion

The White Company has the ability to delete its malware entirely from the target system.

T1124
System Time Discovery

The White Company has checked the current date on the victim system.

T1203
Exploitation for Client Execution

The White Company has taken advantage of a known vulnerability in Microsoft Word (CVE 2012-0158) to execute code.

T1204.002
Malicious File

The White Company has used phishing lure documents that trick users into opening them and infecting their computers.

T1518.001
Security Software Discovery

The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET.

T1566.001
Spearphishing Attachment

The White Company has sent phishing emails with malicious Microsoft Word attachments to victims.

Software2

Campaigns0

None recorded.

References1

  1. Cylance Shaheen Nov 2018 Open source
    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.