SentinelLABS tracked sustained cyberespionage operations against Pakistani law enforcement organizations from February 2024 to April 2026, finding that both China-nexus and India-nexus threat actors converged on Balochistan Police. China-linked actors deployed PlugX, ShadowPad, and Cobalt Strike implants, likely motivated by concerns over attacks on Chinese nationals tied to CPEC infrastructure. India-linked actor TAG-179 (overlapping with Mysterious Elephant/Bitter) used Remcos, likely seeking intelligence on Pakistan's management of the Baloch insurgency. A China-nexus actor also compromised the Balochistan Police Complaint Management System web application, planting fake update implants (cms_plugin.exe) written in Rust and .NET that targeted both police staff and citizens. The compromised systems held biometric records, criminal case files, personnel data, hotel guest logs, and tenant registrations. The report includes full IOCs including C2 IP addresses, SHA-1 hashes, and malware indicators.

16m read timeFrom sentinelone.com
Post cover image
Table of contents
Executive SummaryOverviewStrategic Motives | Distrust and AccusationsIntrusions Into Pakistani Law Enforcement OrganizationsBalochistan Police | Compromised AssetsBalochistan Police | CMS CompromiseConclusionIndicators of Compromise
58 Impressions