AUTO-UPDATED

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers at SentinelOne have identified sustained espionage campaigns by China- and India-aligned threat actors targeting sensitive data within multiple Pakistani law enforcement agencies between 2024 and 2026.

Key Points

  • Threat actors compromised servers and network appliances belonging to the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority.
  • Stolen data includes biometric records, criminal case files, national identity information, and internal personnel documents.
  • Four distinct malware families were deployed: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT.
  • The China-nexus groups utilized custom implants disguised as portal updates within the Balochistan Police Complaint Management System.
  • The India-nexus activity is linked to the hacking group Mysterious Elephant, which shares tactical overlaps with known adversaries like SideWinder and Confucius.

Why it Matters

The convergence of multiple nation-state actors targeting the same law enforcement infrastructure highlights the high strategic value of internal security and citizen data. By weaponizing public-facing portals, these attackers have transformed government service tools into active threats against both police personnel and the general public.
Internet Published by info@thehackernews.com (The Hacker News)
Read original