**Cyber Espionage Targeting Pakistani Law Enforcement: A Multi-Nation Threat Landscape**
Cybersecurity researchers from SentinelOne have uncovered a sophisticated, multi-year cyber espionage campaign targeting Pakistani law enforcement agencies between February 2024 and April 2026. The attacks, attributed to both China-aligned and India-aligned threat actors, represent a significant compromise of national security infrastructure and citizen data.
**A Multi-Victim, Multi-Malware Campaign**
The operation, detailed in a recent SentinelLABS report, did not rely on a single point of entry. Instead, it systematically targeted network appliances and servers integral to managing sensitive citizen and police data. The attackers specifically focused on assets critical to operational function, including:
* **Core Infrastructure:** Network appliances and servers managing criminal records and biometric databases.
* **Citizen-Facing Systems:** Web applications handling hotel and tenant registrations, which are linked to national identity records.
* **Operational & Personnel Data:** Systems containing criminal case files and sensitive personnel records.
One of the most alarming tactics involved the **compromise of the “Complaint Management System” (CMS)**, a web application named `cms.balochistanpolice.gov.pk`. This portal, designed to allow both police staff and citizens to register and track complaints, was hijacked to become a weapon against its users. Attackers deployed a custom implant masquerading as a legitimate portal update, effectively turning a tool of public accountability into a malware delivery mechanism.
**Threat Actor Profiles and Tactics**
SentinelOne identified four distinct threat clusters, each deploying a unique malware family, pointing to a coordinated yet diverse attack landscape:
* **China-Aligned Actors:** Dominated the initial access phase. Two primary malware families were identified:
* **PlugX:** A notorious remote access trojan (RAT) traditionally associated with Chinese state-sponsored or state-aligned groups. Its appearance between February and September 2024 reinforces this attribution.
* **ShadowPad:** A successor to PlugX, detected from August to December 2024, indicating an evolution in the Chinese threat actor’s toolkit. Its victimology extends beyond Pakistan to government, defense, and research entities across Asia and the Arabian Peninsula.
* **India-Aligned Actors:** Represented by the **Remcos RAT**. This intrusion set is linked to a hacking group known as **Mysterious Elephant (APT-C-08)**, which has historical ties to other India-based adversaries like SideWinder and Bitter. Remcos activity was focused on the period between June 2024 and April 2026.
* **Shared Infrastructure:** A cluster using **Cobalt Strike**, a legitimate penetration testing tool often co-opted by attackers, was also detected. Traffic analysis revealed C2 servers directing traffic not only to Pakistani targets but also to a wide range of entities across South Asia, the Middle East, and South America, a hallmark of China-aligned cyber espionage.
The strategic use of lures related to **Pakistani law enforcement**—featuring decoy documents about the repatriation of illegal foreigners, including Afghan Citizen Card holders—demonstrates the attackers’ deep understanding of the operational context and their ability to craft believable social engineering attacks.
**Compromised Assets and Fallout**
The physical and digital breach was extensive. For the Balochistan Police alone, the attackers compromised:
* Two network appliances.
* Web servers hosting multiple applications for the Smart Police Station digitalization initiative.
* A Fortinet FortiMail appliance, which served as the agency’s primary inbound email gateway, effectively granting attackers control over a major communication channel.
**What You Should Know**
**Q: Which organizations were targeted?**
A: The primary targets were the **Balochistan Police**, **Khyber Pakhtunkhwa Police**, **Islamabad Police**, and the **Punjab Safe Cities Authority (PSCA)**.
**Q: What was the “Complaint Management System” and why was it significant?**
A: The CMS (`cms.balochistanpolice.gov.pk`) is a portal for citizens and police staff to register and track complaints. Its compromise was significant because it extended the attacker’s reach directly to both the police personnel and the citizens they serve, turning a public service into a malware distribution platform.
**Q: What were the different types of malware used, and who likely deployed them?**
A: Four main malware families were identified: **PlugX** and **ShadowPad** (associated with China-aligned actors), **Cobalt Strike** (used by various actors, including China-aligned groups), and **Remcos RAT** (linked to an India-aligned threat actor group known as Mysterious Elephant).
**Q: What was the ultimate goal of this espionage campaign?**
A: The goal was intelligence gathering on Pakistan’s internal security apparatus. By compromising the institutions that hold “the government’s internal security picture—what it knows about the threats inside its borders, and how it acts against them”—the attackers gained strategic insights into Pakistan’s law enforcement and national security strategies.
**Conclusion**
The sustained cyber espionage campaign against Pakistani law enforcement is a stark reminder of the evolving threat landscape, where geopolitical rivalries manifest in digital intrusions. The campaign’s sophistication, its targeting of critical citizen-facing infrastructure, and the convergence of multiple nation-state actors against a single set of victims highlight the immense value placed on the intelligence held by these institutions. This operation not only risked the integrity of Pakistan’s law enforcement but also eroded the public trust placed in digital government services, making it a multifaceted national security challenge with long-lasting implications.



