BALOCHISTAN — Cyberespionage groups linked to China and India conducted a coordinated intrusion into Pakistani law enforcement networks from February 2024 through April 2026, according to research by SentinelOne. The Balochistan Police absorbed the majority of the activity. Attackers gained access to servers connected with biometric databases, criminal case files, and personnel records. Citizen-facing systems were also compromised, including the public Complaint Management System, which residents use to file and track grievances. Researchers at SentinelLabs found malicious files disguised as software updates embedded directly into this system. Anyone accessing the site, including police officers and citizens, would have encountered these fake update prompts.
SentinelLabs grouped the intrusions into four clusters based on the malware and infrastructure used, which included PlugX, ShadowPad, Cobalt Strike, and Remcos. Researchers noted that clusters built on shared or commodity malware might involve more than one operator. However, Remcos activity was tied to a single identifiable actor. SentinelLabs linked part of the intrusion to a Chinese-speaking developer based on shared code patterns and artifacts found in related malware samples.
SentinelLabs suggests that the Chinese-linked activity is driven by self-interest. Chinese nationals involved in Belt and Road projects in Pakistan have faced repeated attacks tied to Baloch separatist militants. Chinese officials have criticized Islamabad's efforts to safeguard Chinese nationals. Direct access to Pakistani police data would allow Beijing to assess the threat level independently. The India-linked activity aligns with a long-standing dispute between Islamabad and New Delhi. Pakistan has previously accused India of supporting Baloch militants, an accusation India has denied. New Delhi has an interest in information within Balochistan Police networks regarding Islamabad's management of the insurgency.
Why It Matters
The coordinated cyberespionage campaign against the Balochistan Police indicates sustained efforts by foreign actors to access sensitive Pakistani government data. The compromise of systems containing biometric databases, criminal records, and personnel information could have implications for security and privacy. The infiltration of the public Complaint Management System, a critical interface for citizen interaction with law enforcement, suggests a broad effort to gather information from various levels of police operations and public engagement.
forum Comments (0)
No comments yet. Be the first to comment.