IC Technology & Cyber — 2026-07-11

China and India Espionage Groups Independently Target Pakistani Law Enforcement

BLUFDual penetration of Balochistan Police by competing intelligence services means Pakistani law enforcement databases now function as an unintended bridge between Chinese and Indian collection operations.

SentinelOne (SentinelLabs) reported sustained cyberespionage activity against multiple Pakistani law enforcement organizations between February 2024 and April 2026, attributing intrusions to separate suspected China-nexus and India-nexus threat actors using PlugX, ShadowPad, Cobalt Strike, and Remcos infrastructure 1. Both actor sets converged on Balochistan Police, compromising network appliances and web servers hosting applications that manage biometric records, criminal case files, and personnel data; a suspected China-nexus actor also planted implants in the force's Complaint Management System 1. Additional compromised infrastructure was identified at Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority 12. The Chinese Embassy in Washington said China "firmly opposes and combats all forms of cyberattacks," the Indian Embassy did not respond to questions, and Khyber Pakhtunkhwa Police said no core system had been "successfully compromised" though one user's login credentials were exposed in an isolated incident 23. SentinelLabs identified the India-nexus actor as TAG-179 (also tracked as Mysterious Elephant and Bitter/APT-C-08), assessing its focus on Balochistan security operations as tied to the broader Pakistan-India rivalry, while the China-nexus activity was linked to protecting Chinese nationals under the China-Pakistan Economic Corridor following Balochistan Liberation Army attacks including the October 2024 Karachi airport bombing 1.

Analysis
Suspected China-nexus and India-nexus actors burrowing into the same Balochistan police systems, including the Complaint Management System, points to a structural weakness in Pakistan's internal-security architecture rather than an isolated breach, with compromised infrastructure at Islamabad, Khyber Pakhtunkhwa, and Punjab Safe Cities leaving that penetration uncontained across the force. Khyber Pakhtunkhwa's denial covers only one isolated credential exposure and says nothing about the other three networks, where no comparable statement has emerged. Reporting rests on a single primary disclosure from SentinelLabs, with other outlets amplifying rather than independently corroborating, and the tooling and infrastructure overlap underpinning both nation-state attributions leaves open that shared or resold C2 infrastructure reflects criminal or contractor access rather than two coordinated intelligence services. Either way, Pakistani law enforcement can no longer be assumed to keep a treaty partner's and a rival's collection compartmentalized within its own network.
4 sources
  1. One Target: China-India Espionage Converge on Pakistani Law Enforcement - SentinelOne
  2. China, India-linked hacking groups targeted Pakistani law enforcement, report says - The Express Tribune
  3. China, India-linked hacking groups targeted Pakistani law enforcement, report says - ThePrint
  4. China, India ran separate spying campaigns against same Pakistani police force - The Record from Recorded Future News

View in full brief →

UNCLASSIFIED // OPEN SOURCE