Cybersecurity researchers at SentinelOne SentinelLABS have disclosed details of sustained cyber espionage activity targeting Pakistani law enforcement organizations, including the Balochistan Police, between February 2024 and April 2026. The campaign involves suspected China- and India-aligned threat actors compromising network appliances and web servers hosting applications that manage biometric records, criminal case files, and personnel data.
At Balochistan Police, attackers compromised the Complaint Management System (CMS) web application, deploying custom implants masquerading as portal updates. Two variants of an implant called ‘cms_plugin.exe’ were identified: a Rust stager that downloads additional payloads, and a .NET executable masquerading as ‘360Safe.exe’ to load an AsyncRAT client. Other affected organizations include Khyber Pakhtunkhwa Police, Islamabad Police, and Punjab Safe Cities Authority (PSCA).
Four threat clusters were flagged, each deploying unique malware families: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The Remcos RAT cluster is linked to an India-nexus threat actor with overlaps to the Mysterious Elephant group (APT-C-08, APT-K-47, TAG-179), while PlugX, ShadowPad, and Cobalt Strike clusters are associated with China-nexus actors. Attack chains used lures related to Pakistani law enforcement, such as decoy documents about repatriation of illegal foreigners.
The compromise of the CMS portal turned a citizen-facing tool into a malware delivery mechanism, extending the threat actor’s reach beyond the initially compromised environment. This convergence of multiple espionage actors targeting the same victim signals high target value, driven by geopolitical motives.
Attack groups: Mysterious Elephant, SideWinder, Confucius, Bitter
Malware: PlugX, ShadowPad, Cobalt Strike, Remcos RAT, AsyncRAT
Companies: SentinelOne, Qihoo 360, Fortinet
Products: Fortinet FortiMail, 360 Total Security
Original source: thehackernews.com