China- and India-linked cyberespionage campaign against Pakistani law enforcement
Campaign
Summary
Hide ▲
Show ▼
Suspected China- and India-aligned threat actors ran a Feb 2024–Apr 2026 cyberespionage campaign against Pakistani law enforcement, with Balochistan Police and other agencies exposed to intrusions tied to biometric records, criminal case files, personnel records, and public-service systems. The activity was split across PlugX, ShadowPad, Cobalt Strike, and Remcos RAT clusters, and it included fake portal updates and a fake 360Safe.exe loader on the Complaint Management System (CMS).
Related Happenings
China- and India-nexus espionage campaign targeting Pakistani police
Campaign
H score35
First: 13.07.2026 17:45
Last: 13.07.2026 17:45
Sources 1
About this happening:
A China- and India-nexus espionage campaign targeted Pakistani law enforcement over an extended period, putting sensitive police and identity records at risk. The operatio...
China- and India-nexus espionage campaign targeting Pakistani police
CampaignAbout this happening: A China- and India-nexus espionage campaign targeted Pakistani law enforcement over an extended period, putting sensitive police and identity records at risk. The operatio...
Balochistan Police hit by network compromise
Incident
H score25
First: 11.07.2026 20:49
Last: 11.07.2026 20:49
Sources 1
How related:
At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records," Aleksandar Milenkoski, principal threat researcher at SentinelOne SentinelLABS, said in a report published this week.
About this happening:
Balochistan Police suffered a long-running compromise of police infrastructure and a public-facing Complaint Management System (CMS), with exposure spanning June 2,...
Balochistan Police hit by network compromise
IncidentHow related: At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records," Aleksandar Milenkoski, principal threat researcher at SentinelOne SentinelLABS, said in a report published this week.
About this happening: Balochistan Police suffered a long-running compromise of police infrastructure and a public-facing Complaint Management System (CMS), with exposure spanning June 2,...
NCSC-UK joint advisory on covert botnets and proxy networks
Public Sector Action
H score66
First: 23.04.2026 15:28
Last: 23.04.2026 15:28
Sources 1
About this happening:
NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...
NCSC-UK joint advisory on covert botnets and proxy networks
Public Sector ActionAbout this happening: NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...
Timeline
-
10.07.2026 14:55 3 articles · 13d ago
China- and India-linked intrusions target Pakistani police networks
Initial DisclosureSentinelLabs reported a sustained cyberespionage campaign against Pakistani law enforcement networks, with Balochistan Police absorbing most of the activity and several police organizations affected. The activity was grouped into PlugX, ShadowPad, Cobalt Strike, and Remcos clusters, with some access reaching servers tied to biometric databases, criminal case files, personnel records, and citizen-facing systems. Researchers also identified malicious files disguised as software updates on Balochistan Police’s public Complaint Management System, which could affect officers and residents using the portal.
Show sources
- China, India-Linked Hackers Both Targeted Same Pakistani Police Force — www.securityweek.com — 10.07.2026 14:55
- China, India-Linked Hackers Both Targeted Same Pakistani Police Force — www.securityweek.com — 10.07.2026 14:55
- Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns — thehackernews.com — 11.07.2026 20:49