THE WHITE COMPANY
G0089
UNKNOWN
APT
Threat IntelligenceAPTFebruary 24, 2026

The White Company Threat Profile

Sophisticated group targeting Pakistani military and nuclear program with malware designed to evade 8+ antivirus products.

Sophisticated group targeting Pakistani military and nuclear program with malware designed to evade 8+ antivirus products. This profile is mapped to MITRE ATT&CK G0089 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

The White Company (also tracked as None publicly documented) is a threat group attributed to Unknown. The group primarily targets Pakistani military, nuclear for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0089 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with The White Company include:

Targeting & Operations

The White Company operations focus on Pakistani military, nuclear. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the Pakistani military sector should treat The White Company as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in The White Company operations:

Technique IDTechnique NameTactical Context
T1566.001T1566.001Observed in The White Company campaigns
T1027T1027Observed in The White Company campaigns
T1059.001T1059.001Observed in The White Company campaigns
T1071.001T1071.001Observed in The White Company campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0089/

Notable Campaigns

This threat group has been active in operations targeting Pakistani military, nuclear. Security researchers have documented campaigns involving Custom AV-evasion frameworks and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to Unknown-nexus operations.

Detection & Defense

Recommended defensive measures against The White Company:

How Mjolnir Security Can Help

Defend Against The White Company

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against Unknown-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: February 24, 2026