Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

0
Medium
Published: 07/09/2026 (07/09/2026, 22:16:04 UTC)
Source: AlienVault OTX General

Description

Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 12:41:43 UTC

Technical Analysis

This threat involves sustained cyberespionage intrusions by multiple threat actors with suspected ties to China and India targeting Pakistani law enforcement agencies, particularly the Balochistan Police, from early 2024 through mid-2026. The attackers compromised infrastructure including network appliances and servers running web applications related to criminal records, biometric data, and citizen services. A China-nexus actor weaponized the Complaint Management System by deploying custom implants disguised as portal updates, affecting both police personnel and citizens. The operations leveraged a range of malware and tools including PlugX, ShadowPad, Cobalt Strike, Remcos, and others. The geopolitical motivations are linked to Chinese concerns over nationals' safety in Pakistan and India's interest in intelligence on security operations in a strategic province. The campaign reflects converging espionage interests from rival states targeting sensitive law enforcement data.

Potential Impact

The intrusions compromised critical law enforcement infrastructure in Pakistan, potentially exposing sensitive criminal records, biometric data, hotel registrations, and citizen complaints. The deployment of implants and advanced malware tools could enable persistent espionage, data exfiltration, and operational disruption. The targeting of both personnel and citizens through weaponized web applications increases the scope of impact. The espionage activities may undermine law enforcement confidentiality and regional security.

Defensive Guidance

No specific patch or remediation is indicated for this threat as it involves targeted cyberespionage operations rather than a software vulnerability. Organizations should follow best practices for securing web applications and network appliances, monitor for indicators of compromise related to the mentioned malware families, and apply threat intelligence updates from trusted sources. Since this is an ongoing espionage campaign, continuous monitoring and incident response preparedness are advised.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"]
Adversary
TAG-179
Pulse Id
6a501da43fb3cb230cc9a9b9
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip172.94.9.19
CC=DE ASN=AS3223 voxility llp
ip172.94.9.19
ip172.111.233.105
CC=US ASN=AS9009 m247 ltd
ip172.111.233.96
CC=US ASN=AS9009 m247 ltd
ip142.171.183.8
CC=CA ASN=AS577 bell canada
ip172.111.233.12
CC=US ASN=AS9009 m247 ltd
ip193.42.25.65
CC=HK ASN=AS55933 cloudie limited
ip45.125.32.218
CC=HK ASN=AS55933 cloudie limited
ip89.31.121.220
CC=RS ASN=AS9009 m247 ltd
ip172.94.9.43
CC=DE ASN=AS3223 voxility llp
ip172.94.9.43
ip172.94.9.49
CC=DE ASN=AS3223 voxility llp
ip172.94.9.49
ip41.216.188.140
ip41.216.188.140
CC=US ASN=AS211138 private-hosting di cipriano oscar
ip172.111.233.26
CC=US ASN=AS9009 m247 ltd
ip172.111.233.36
CC=US ASN=AS9009 m247 ltd
ip45.74.6.17
CC=BE ASN=AS9009 m247 ltd

Domain

ValueDescriptionCopy
domaincms.balochistanpolice.gov.pk
domaincms.balochistanpolice.gov.pk

Hash

ValueDescriptionCopy
hashfc59fc3d4b2af739014de04428ce2fb5
hashfc59fc3d4b2af739014de04428ce2fb5
MD5 of 2bab40c55637398f0497cff9c8cbea564d595c7f
hashd92fac74e6d7f4d8fc96c9ce6239435f
hashd92fac74e6d7f4d8fc96c9ce6239435f
MD5 of 539bd79fbb684edea94eb37518134b97e94b9dd8
hash000fad96a85dd6933c22d3dbec9aed47b7f1f066
hash000fad96a85dd6933c22d3dbec9aed47b7f1f066
hashc6c197e61079a0a33108c2c87b5e3c7056a138ec
hashc6c197e61079a0a33108c2c87b5e3c7056a138ec
hash96b15bb9ce8ef7c41b708b1620029d99
hash96b15bb9ce8ef7c41b708b1620029d99
MD5 of 6fe2e74d009abbd56de01fd7404a1245e9b47c79
hash91693c2d5a4b7d090fe06cc7382dfc18
hash91693c2d5a4b7d090fe06cc7382dfc18
MD5 of 47f8cb0c2dcf62702f58cfc1603d6325755f6820
hash08570471f39bb6725f07b8cddbea99ed48c22686
hash08570471f39bb6725f07b8cddbea99ed48c22686
hash23f4766c011d193f076dfc735dc460e2a41ead79
hash23f4766c011d193f076dfc735dc460e2a41ead79
hash23f6781919a50b118d8d4e6a7e9ae63b71ecc885
hash23f6781919a50b118d8d4e6a7e9ae63b71ecc885
hash2bab40c55637398f0497cff9c8cbea564d595c7f
hash2bab40c55637398f0497cff9c8cbea564d595c7f
hash4039454c9189e64285e93fc075a30b93f814b5b5
hash4039454c9189e64285e93fc075a30b93f814b5b5
hash47f8cb0c2dcf62702f58cfc1603d6325755f6820
hash47f8cb0c2dcf62702f58cfc1603d6325755f6820
hash539bd79fbb684edea94eb37518134b97e94b9dd8
hash539bd79fbb684edea94eb37518134b97e94b9dd8
hash58cb2d95063b9df807b7aa8dc106b74ce988a491
hash58cb2d95063b9df807b7aa8dc106b74ce988a491
hash5d60ff36ff519c2e13e7f66cfa0bb46be79592a7
hash5d60ff36ff519c2e13e7f66cfa0bb46be79592a7
hash63b88d00331de88af696dfb7a896935d830e485f
hash63b88d00331de88af696dfb7a896935d830e485f
hash6fe2e74d009abbd56de01fd7404a1245e9b47c79
hash6fe2e74d009abbd56de01fd7404a1245e9b47c79
hash71757adba833b46f961e840d0f055bcce0b529c4
hash71757adba833b46f961e840d0f055bcce0b529c4
hash8c329db96e093fa25268e078405a33c518dbb5c9
hash8c329db96e093fa25268e078405a33c518dbb5c9
hashd66ab0cd2e44dc8389c111b7ed34c7bcb0b35311
hashd66ab0cd2e44dc8389c111b7ed34c7bcb0b35311
hash1fd8ba64a687247466fa6e8b7d194154439ef527746fdb8c18b3c3d65b6d2390
SHA256 of 2bab40c55637398f0497cff9c8cbea564d595c7f
hash1fd8ba64a687247466fa6e8b7d194154439ef527746fdb8c18b3c3d65b6d2390
hash71fa6a00314701fef5c6f32c17e1438063d05616198ac9a12004aeab957e11ae
SHA256 of 539bd79fbb684edea94eb37518134b97e94b9dd8
hash71fa6a00314701fef5c6f32c17e1438063d05616198ac9a12004aeab957e11ae
hash7ea0930a332788c2e88e5822e4908d77cdcaad57e0e97401ed8fe4b117fdfc95
hash7ea0930a332788c2e88e5822e4908d77cdcaad57e0e97401ed8fe4b117fdfc95
SHA256 of 6fe2e74d009abbd56de01fd7404a1245e9b47c79
hash9fb6f4c55e5198739123264f8007cf6e22b3821af97a00a471bd54b30991ecd0
hash9fb6f4c55e5198739123264f8007cf6e22b3821af97a00a471bd54b30991ecd0
SHA256 of 47f8cb0c2dcf62702f58cfc1603d6325755f6820

Url

ValueDescriptionCopy
urlhttp://cms.balochistanpolice.gov.pk/client%20scripts/
urlhttp://cms.balochistanpolice.gov.pk/client%20scripts/cms_plugin.exe
urlhttp://cms.balochistanpolice.gov.pk/client%20scripts/cms_plugin.exe

Threat ID: 6a50a39468715ace433baa42

Added to database: 07/10/2026, 07:47:32 UTC

Last enriched: 08/09/2026, 12:41:43 UTC

Last updated: 08/24/2026, 04:22:24 UTC

Views: 156

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses