A targeted spear-phishing campaign hit employees at Pakistan's Punjab Safe Cities Authority (PSCA) and the Punjab Police Integrated Command, Control & Communication Centre (PPIC3), with attackers impersonating an internal consultant and using "Safe Jail Project" lures to make the emails appear legitimate. The messages carried both a malicious Word document and a PDF with misspelled filenames; the Word file relied on a VBA macro and VBA stomping to conceal malicious code, while the PDF presented a fake Adobe Reader error that pushed victims toward a bogus update flow.
The operation used staged payload delivery to evade detection, including downloads from BunnyCDN infrastructure and a malicious ClickOnce application that retrieved payloads such as code.exe and Adobe.exe. Researchers said the malware established persistence and remote access through Microsoft Visual Studio Code tunneling and used Discord webhooks to signal compromise and potentially support data theft or exfiltration. Analysis by Joe Sandbox and JoeReverser indicated the toolset was likely custom-built for the campaign and did not match any known malware family in Malpedia.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Analysis by JoeReverser and Joe Sandbox found no match to a known malware family in Malpedia, indicating the malware used in the Pakistan-targeting campaign was likely developed specifically for this operation.
Once executed, the malware established persistent remote access using Microsoft Visual Studio Code tunneling services for command-and-control and sent compromise notifications through Discord webhooks, supporting ongoing access and possible data theft or exfiltration.
The Word attachment used malicious VBA macros and VBA stomping to conceal code that downloaded a payload such as 'code.exe' after users enabled content, while the PDF showed a fake Adobe Reader error to lure victims into downloading a malicious ClickOnce application that fetched another payload. The campaign relied on staged delivery and infrastructure including BunnyCDN to evade detection.
Attackers launched a targeted phishing operation against staff at the Punjab Safe Cities Authority and the Punjab Police Integrated Command, Control & Communication Centre, impersonating an internal consultant and using a 'Safe Jail Project' theme to increase credibility. The emails carried both a malicious Word document and a PDF attachment to deliver malware through separate infection paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.