Cybersecurity researchers at SentinelOne have identified sustained espionage campaigns by China- and India-aligned threat actors targeting sensitive data within multiple Pakistani law enforcement agencies between 2024 and 2026.
Key Points
- Threat actors compromised servers and network appliances belonging to the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority.
- Stolen data includes biometric records, criminal case files, national identity information, and internal personnel documents.
- Four distinct malware families were deployed: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT.
- The China-nexus groups utilized custom implants disguised as portal updates within the Balochistan Police Complaint Management System.
- The India-nexus activity is linked to the hacking group Mysterious Elephant, which shares tactical overlaps with known adversaries like SideWinder and Confucius.