The White Company Series: Operation Shaheen Report
ID: c9424f9d-b574-4478-b97f-defa3aca7295
STIX ID: report--c9424f9d-b574-4478-b97f-defa3aca7295
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-11-08
Last Modified Date: 2018-11-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cylance report (The White Company series) analyzes "Operation Shaheen," a year-long targeted espionage campaign against Pakistani government and military (notably the Pakistan Air Force). It documents a two-phase exploitation chain (initially CVE-2012-0158/CVE-2015-1641/CVE-2016-7193 usage), complex multi-stage shellcode with unusual AV-evasion and timed surrender behavior, heavy obfuscation (nesting/packing), use of public RATs (Revenge-RAT, NetWire) as payloads, isolated C2 infrastructure, and genetic/version mapping of exploit development; the authors assess the operator as a likely state-sponsored group with access to zero-day exploits and a sophisticated build system.
