How two rivals, China and India, converged on the same Pakistani police servers
Between February 2024 and April 2026, China- and India-nexus cyberespionage actors compromised networks belonging to several Pakistani law enforcement organizations. All of them reached Balochistan Police, the force serving a province shaped by a separatist insurgency and the regional tensions it has drawn in.
Attributions follow the SentinelLABS assessment and cited secondary sources. The convergence on the same victim class is a documented signal.
Two regional powers with opposing motives reach the same data. For China, the most likely driver is the safety of Chinese nationals repeatedly attacked on Pakistani soil. For India, it is visibility into an adversary in the province at the center of their rivalry.
The densest concentration of intrusions was at Balochistan Police, but activity extended to Khyber Pakhtunkhwa Police, Islamabad Police, and Punjab Safe Cities Authority.
Four activity clusters, grouped by tooling: PlugX, ShadowPad, Cobalt Strike, and Remcos. Between October and November 2024, three clusters were active simultaneously against Balochistan Police.
The affected servers hosted web applications from the Smart Police Station initiative, an EU-supported program to modernize policing. The potentially accessible data covered criminal case files, biometrics, hotel registrations, personnel, and citizen complaints.
Application for FIR registration and management. FIRs are documents prepared by police upon receiving information about the commission of a cognisable offence.
Personnel database managing officer service records, transfers, postings, payroll, and performance evaluations.
Database for tracking stolen vehicles, their recovery, and investigation.
Hotel guest check-in logging, integrated with NADRA identity records to notify police when individuals with criminal records check in.
Criminal records database with fingerprint-based biometric matching.
Landlord-tenant registration platform integrated with criminal records.
Platform for registering, tracking, and resolving citizen complaints: reports of crime, loss of documents, complaints about police misconduct.
The Complaint Management System (CMS) is the portal through which police staff and citizens interact with Balochistan Police. The threat actor deployed implants disguised as a portal update, turning a public digitalization tool into a malware delivery mechanism.
cms.balochistanpolice.gov.pk
Restricted access. Credentials of the form ps-[district]. Case files, complaints, case management.
Open access. Citizens check complaint status using a reference number and phone number.
Two variants of cms_plugin.exe deployed in /client scripts/:
1. Rust stager: downloads payload from 193.42.25[.]65
2. .NET/AsyncRAT: disguised as 360Safe.exe, connecting to 41.216.188[.]140. PDB path: D:\codedome\... Chinese-speaking developer indicators (pinyin, simplified Chinese log messages).
SHA-1 hashes, IP addresses, and URLs from the SentinelLABS report. Click a value to copy it.
| Type | Value | Note |
|---|---|---|
| SHA-1 | 000fad96a85dd6933c22d3dbec9aed47b7f1f066 | Backdoor launcher (TAG-179) |
| SHA-1 | 08570471f39bb6725f07b8cddbea99ed48c22686 | Backdoor launcher (TAG-179) |
| SHA-1 | 23f4766c011d193f076dfc735dc460e2a41ead79 | Backdoor launcher (TAG-179) |
| SHA-1 | 23f6781919a50b118d8d4e6a7e9ae63b71ecc885 | cms_plugin.exe |
| SHA-1 | 2bab40c55637398f0497cff9c8cbea564d595c7f | Lure file (TAG-179) |
| SHA-1 | 4039454c9189e64285e93fc075a30b93f814b5b5 | cms_plugin.exe |
| SHA-1 | 47f8cb0c2dcf62702f58cfc1603d6325755f6820 | Backdoor launcher (TAG-179) |
| SHA-1 | 539bd79fbb684edea94eb37518134b97e94b9dd8 | Lure file (TAG-179) |
| SHA-1 | 58cb2d95063b9df807b7aa8dc106b74ce988a491 | cms_plugin.exe |
| SHA-1 | 5d60ff36ff519c2e13e7f66cfa0bb46be79592a7 | Backdoor (TAG-179) |
| SHA-1 | 63b88d00331de88af696dfb7a896935d830e485f | Backdoor (TAG-179) |
| SHA-1 | 6fe2e74d009abbd56de01fd7404a1245e9b47c79 | Lure file (TAG-179) |
| SHA-1 | 71757adba833b46f961e840d0f055bcce0b529c4 | Lure file (TAG-179) |
| SHA-1 | 8c329db96e093fa25268e078405a33c518dbb5c9 | Backdoor (TAG-179) |
| SHA-1 | c6c197e61079a0a33108c2c87b5e3c7056a138ec | Lure file (TAG-179) |
| SHA-1 | d66ab0cd2e44dc8389c111b7ed34c7bcb0b35311 | Backdoor (TAG-179) |
| IP | 142.171.183[.]8 | Cobalt Strike C2 server |
| IP | 172.111.233[.]105 | PlugX C2 server |
| IP | 172.111.233[.]12 | PlugX C2 server |
| IP | 172.111.233[.]26 | PlugX C2 server |
| IP | 172.111.233[.]36 | PlugX C2 server |
| IP | 172.111.233[.]96 | PlugX C2 server |
| IP | 172.94.9[.]19 | PlugX C2 server |
| IP | 172.94.9[.]43 | PlugX C2 server |
| IP | 172.94.9[.]49 | PlugX C2 server |
| IP | 193.42.25[.]65 | Cobalt Strike C2 server |
| IP | 41.216.188[.]140 | AsyncRAT C2 server |
| IP | 45.125.32[.]218 | ShadowPad C2 server |
| IP | 45.74.6[.]17 | PlugX C2 server |
| IP | 89.31.121[.]220 | Remcos C2 server |
| URL | https[://]cms.balochistanpolice[.]gov[.]pk/client%20scripts/cms_plugin.exe | Implant-hosting URL on the CMS portal |
Factual basis for this page: intrusions, C2 clusters, IOCs, CMS compromise, attributions and strategic motives.
Attribution of Remcos server 89.31.121[.]220 to TAG-179.
Documentation of TAG-179 / APT-C-08 tooling and infection chains, including Remcos with the same C2 server.
TTP overlaps with TAG-179 / APT-C-08.