Multiple Pakistani law enforcement organizations were subjected to sustained cyberespionage intrusions between February 2024 and April 2026, with Balochistan Police identified as the most heavily targeted victim. SentinelLABS reported that suspected China-linked and India-linked operators used tools and infrastructure including PlugX, ShadowPad, Cobalt Strike, and Remcos to compromise police web servers, network appliances, and a Fortinet FortiMail appliance, gaining access to environments that handled highly sensitive operational and personal data.
A suspected China-linked actor also compromised the Balochistan Police Complaint Management System (CMS) and used the public-facing portal to host malware implants, effectively turning a citizen service into a malware delivery channel. The affected systems contained biometric records, criminal case files, hotel and tenant registrations, personnel records, and citizen complaints, creating surveillance and exposure risks for both police staff and members of the public; researchers assessed the likely objectives as intelligence collection on threats to Chinese nationals in Pakistan and on Pakistan’s security posture in Balochistan.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers said the compromised infrastructure in the espionage campaign was associated with Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority, in addition to Balochistan Police. The affected systems hosted web applications managing sensitive police and citizen data, including criminal records, biometric data, registrations, and personnel files.
The intrusions against Pakistani law enforcement organizations continued through April 2026, involving suspected China-nexus and India-nexus actors. The activity used PlugX, ShadowPad, Cobalt Strike, and Remcos against police web servers, network appliances, and a Fortinet FortiMail appliance.
A suspected China-nexus actor compromised the Balochistan Police Complaint Management System and hosted malware implants on the portal. This turned a police-and-citizen service into a malware delivery mechanism that could expose police personnel and citizens to infection and surveillance.
SentinelLABS reported that sustained cyberespionage intrusions targeting multiple Pakistani law enforcement organizations began in February 2024. Balochistan Police was identified as the most heavily targeted victim.
In late 2024, attackers uploaded two cms_plugin.exe variants to the Balochistan Police Complaint Management System: a Rust-based stager and a .NET implant masquerading as Qihoo 360 software that loaded an AsyncRAT client. SentinelLabs said shared code and simplified Chinese strings suggested a Chinese-speaking developer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceinfosecurity-magazine.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcetherecord.media
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.