Infosecurity

Two Rivals, One Target: How Chinese and Indian Hackers Infiltrated Pakistan’s Police Networks

Published

on

For months, two of the world’s most sophisticated cyber espionage operations were quietly working the same beat: the digital backbone of Pakistan’s police forces. One linked to Beijing. The other to New Delhi. Both after the same sensitive data.

New research from SentinelOne‘s SentinelLabs, published July 9, reveals that suspected China- and India-nexus actors ran parallel intrusion campaigns against several Pakistani law enforcement bodies between February 2024 and April 2026. The primary target: Balochistan Police, the province’s main force.

This is a story about espionage, sure. But it’s also a story about what happens when rival nations see the same vulnerable target and decide it’s worth the risk.

What the Attackers Got Access To

The compromised assets weren’t just email accounts or routine administrative systems. These were servers hosting the kind of data that makes intelligence analysts salivate:

  • Biometric records and fingerprint databases
  • Criminal case files
  • Tenant and landlord registrations tied to national identity data
  • Police personnel and payroll records
  • Stolen vehicle records
  • Hotel check-ins linked to identity information
  • Citizen complaints, including misconduct reports

One China-nexus actor reportedly planted implants in a portal used by both officers and citizens. The scale is staggering — and the implications for privacy and national security are profound.

Four Clusters, Two Adversaries

SentinelLabs grouped the command and control (C2) activity into four distinct clusters. The technical fingerprints tell a clear story of attribution.

PlugX, ShadowPad and Cobalt Strike — all well-known tools in the Chinese cyber arsenal — point to China-nexus operators. A separate Remcos cluster was tied to a suspected India-nexus actor that Recorded Future tracks as TAG-179, a group that overlaps with what others call Bitter.

Two rivals. Opposite motives. Same battlefield.

Why China Wanted the Data

For China, the likely driver was the safety of its nationals. The China-Pakistan Economic Corridor (CPEC) has poured billions into the region, and Chinese workers have faced repeated deadly attacks there. Some of those attacks were claimed by the Balochistan Liberation Army (BLA), a separatist group that has made targeting Chinese interests a centerpiece of its strategy.

Police data would allow China to assess that threat independently — without relying on Pakistani assurances. It’s a classic intelligence move: verify what your ally tells you, using their own records.

India’s Angle: The Rivalry Next Door

India’s motive is less about protecting citizens and more about the enduring rivalry with Pakistan, in which Balochistan is a recurring flashpoint.

Islamabad has long accused New Delhi of backing the Baloch insurgency — an accusation India denies. The police force holds the record of how Pakistan polices the province. For Indian intelligence, that’s a goldmine of operational insight.

The convergence of these two campaigns isn’t a coincidence. It’s a reflection of how Balochistan has become a geopolitical chessboard where information is the most valuable currency.

The Citizen Portal That Turned Against Its Users

The standout finding was the compromise of the force’s Complaint Management System (CMS), a portal used by both officers and citizens to track complaints. Two variants of an implant named cms_plugin.exe were uploaded in late 2024.

One variant, written in Rust, is a stager that on execution displayed a reassuring message: “Update Complete! Please refresh the page.” It mimicked a routine portal update. Users had no reason to suspect anything was wrong.

The other variant, built in .NET, posed as a component of Chinese vendor Qihoo 360‘s security software. It loaded an AsyncRAT client, giving the attackers remote control over infected machines. Shared code and simplified Chinese strings pointed to a Chinese-speaking developer.

A Structural Risk in Digital Policing

The convergence of these campaigns reflects a deeper problem. Systems that centralize records and services also concentrate intelligence value. Police infrastructure has become intelligence terrain for any capable adversary.

This isn’t just a Pakistani problem. Every country that digitizes law enforcement data creates a similar honeypot. The question is whether the security posture matches the sensitivity of the data.

For Balochistan Police, the answer appears to be no. And when two rival nations both figured that out, the result was a silent war fought over servers and databases — with citizens’ most personal data caught in the crossfire.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version