Find notable cyber news and cases, enriched with sources, timelines, and signals.

Balochistan Police hit by network compromise

Incident
First reported
Last updated
Happening score
H score 25
2 unique sources, 2 articles

Summary

Hide ▲

Balochistan Police suffered a long-running compromise of police infrastructure and a public-facing Complaint Management System (CMS), with exposure spanning June 2, 2024 to April 9, 2026. The affected environment included systems handling criminal records, biometric records, personnel records, and complaint workflows, and the CMS at cms.balochistanpolice.gov[.]pk was used by both officers and citizens. Attackers uploaded cms_plugin.exe implants, including a Rust stager that showed "Update Complete! Please refresh the page," and a .NET loader that masqueraded as 360Safe.exe and reflectively loaded AsyncRAT. The activity is tied in reporting to China-nexus and India-nexus espionage operations, with observed tooling including PlugX, ShadowPad, Cobalt Strike, Remcos, and AsyncRAT.

Related Happenings

China- and India-nexus espionage campaign targeting Pakistani police

Campaign
H score35 First: 13.07.2026 17:45 Last: 13.07.2026 17:45 Sources 1

How related: suspected China- and India-nexus actors ran intrusion campaigns against several Pakistani law enforcement bodies between February 2024 and April 2026, concentrating on Balochistan Police, the province's main force.

About this happening: A China- and India-nexus espionage campaign targeted Pakistani law enforcement over an extended period, putting sensitive police and identity records at risk. The operatio...

China- and India-linked cyberespionage campaign against Pakistani law enforcement

Campaign
H score35 First: 10.07.2026 14:55 Last: 10.07.2026 14:55 Sources 1

How related: Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026.

About this happening: Suspected China- and India-aligned threat actors ran a Feb 2024–Apr 2026 cyberespionage campaign against Pakistani law enforcement, with Balochistan Police and oth...

MuddyWater broad cyber-espionage campaign across sectors and countries

Campaign
H score37 First: 14.05.2026 00:59 Last: 14.05.2026 00:59 Sources 1

About this happening: MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...

APT28 FrostArmada DNS hijacking and AitM credential theft campaign

Campaign
H score45 First: 07.04.2026 18:51 Last: 07.04.2026 18:51 Sources 1

About this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...

Timeline

  1. 11.07.2026 20:49 2 articles · 13d ago

    Balochistan Police web servers and FortiMail gateway are compromised

    Campaign Scope Update

    Compromised Balochistan Police assets included two network appliances, web servers hosting Smart Police Station applications, and a Fortinet FortiMail appliance that served as the agency's primary inbound email gateway, affecting systems that manage criminal, biometric, and personnel records.

    Show sources
  2. 11.07.2026 20:49 2 articles · 13d ago

    Complaint Management System is turned into a malware delivery mechanism

    Technical Analysis Update

    The Complaint Management System (cms.balochistanpolice.gov[.]pk), used by police staff and citizens to register, track, and resolve complaints, hosted two cms_plugin.exe implants: a Rust stager that fetched a payload from 193.42.25[.]65 and a .NET loader masquerading as 360Safe.exe that reflectively loaded an AsyncRAT client.

    Show sources