One Target, Two Flags

How two rivals, China and India, converged on the same Pakistani police servers

Between February 2024 and April 2026, China- and India-nexus cyberespionage actors compromised networks belonging to several Pakistani law enforcement organizations. All of them reached Balochistan Police, the force serving a province shaped by a separatist insurgency and the regional tensions it has drawn in.

SentinelLABS 9 July 2026 Feb 2024 – Apr 2026 4 organizations 4 C2 clusters 14 C2 servers

Attributions follow the SentinelLABS assessment and cited secondary sources. The convergence on the same victim class is a documented signal.

Why Pakistani law enforcement?

Two regional powers with opposing motives reach the same data. For China, the most likely driver is the safety of Chinese nationals repeatedly attacked on Pakistani soil. For India, it is visibility into an adversary in the province at the center of their rivalry.

China: the partner who does not rely on the partner

Relationship Strategic partner. CPEC (China-Pakistan Economic Corridor), flagship Belt and Road program.
Objective Independent assessment of threats to Chinese nationals in Pakistan.
Facts fact Repeated attacks: Karachi airport attack (Oct 2024), suicide bombing in NW Pakistan (Mar 2024). China's ambassador: security situation "unacceptable". Jan 2026: agreement to expand counter-terrorism coordination.
Interpretation interpretation Collection likely aims at independent threat assessment, driven by the need not to rely solely on the partner's protection.

India: the adversary monitoring the adversary

Relationship Adversary. Long-standing security rivalry, mutual accusations of cross-border support for militants.
Objective Visibility into Pakistan's security posture in Balochistan, the province central to mutual accusations.
Facts fact Pakistan accuses India of backing the BLA (Balochistan Liberation Army), calling it an "Indian proxy". India denies. The accusations are not publicly substantiated.
Interpretation interpretation Access to Balochistan Police data would give India visibility into the security of a province central to the bilateral antagonism.

Four provinces, two actors, the same networks

The densest concentration of intrusions was at Balochistan Police, but activity extended to Khyber Pakhtunkhwa Police, Islamabad Police, and Punjab Safe Cities Authority.

Balochistan KPK Punjab Islamabad Sindh China-nexus PlugX · ShadowPad · Cobalt Strike India-nexus Remcos (TAG-179) Balochistan Police KPK Police PSCA Punjab
China-nexus India-nexus Convergence

26 months of C2 activity

Four activity clusters, grouped by tooling: PlugX, ShadowPad, Cobalt Strike, and Remcos. Between October and November 2024, three clusters were active simultaneously against Balochistan Police.

2024-022024-062024-102025-022025-062025-102026-02
Overlap: 3 clusters active
China-nexus
PlugX
PlugX
2024-02-27 – 2024-09-28
9 C2 servers. Victimology: government, foreign affairs, defense, NGOs, research (South, SE, Central and East Asia, Arabian Peninsula, SE Europe).
ShadowPad
ShadowPad
2024-11-05 – 2024-11-29
1 C2 server (45.125.32[.]218). Short activity window, November 2024.
Cobalt Strike
Cobalt Strike
2024-10-12 – 2025-12-05
2 C2 servers. Broad victimology: government, academic, telecom, NGOs (South, East, SE Asia, Middle East, South America). Includes Tibetan Buddhist organizations in Taiwan.
India-nexus
Remcos (TAG-179)
Remcos (TAG-179)
2026-01-13 – 2026-04-09
1 C2 server (89.31.121[.]220). Attributed to TAG-179, linked to Mysterious Elephant / APT-C-08 (Bitter). Lures relevant to illegal foreigners repatriation operations.

What systems were compromised at Balochistan Police?

The affected servers hosted web applications from the Smart Police Station initiative, an EU-supported program to modernize policing. The potentially accessible data covered criminal case files, biometrics, hotel registrations, personnel, and citizen complaints.

FIR

First Information Report

Application for FIR registration and management. FIRs are documents prepared by police upon receiving information about the commission of a cognisable offence.

HRMIS

Human Resource Management

Personnel database managing officer service records, transfers, postings, payroll, and performance evaluations.

AVLS

Anti-Vehicle Lifting System

Database for tracking stolen vehicles, their recovery, and investigation.

HotelEye

HotelEye

Hotel guest check-in logging, integrated with NADRA identity records to notify police when individuals with criminal records check in.

CRMS

Criminal Record Management

Criminal records database with fingerprint-based biometric matching.

TRS

Tenant Registration System

Landlord-tenant registration platform integrated with criminal records.

CMS

Complaint Management System

Platform for registering, tracking, and resolving citizen complaints: reports of crime, loss of documents, complaints about police misconduct.

The portal transformed: from complaint to implant

The Complaint Management System (CMS) is the portal through which police staff and citizens interact with Balochistan Police. The threat actor deployed implants disguised as a portal update, turning a public digitalization tool into a malware delivery mechanism.

cms.balochistanpolice.gov.pk

🔒
Police Login

Restricted access. Credentials of the form ps-[district]. Case files, complaints, case management.

🔍
Public Search

Open access. Citizens check complaint status using a reference number and phone number.

Implant detected

Two variants of cms_plugin.exe deployed in /client scripts/:
1. Rust stager: downloads payload from 193.42.25[.]65
2. .NET/AsyncRAT: disguised as 360Safe.exe, connecting to 41.216.188[.]140. PDB path: D:\codedome\... Chinese-speaking developer indicators (pinyin, simplified Chinese log messages).

✓ Update Complete! Please refresh the page.

Indicators of Compromise

SHA-1 hashes, IP addresses, and URLs from the SentinelLABS report. Click a value to copy it.

31 of 31 indicators
Type Value Note
SHA-1000fad96a85dd6933c22d3dbec9aed47b7f1f066Backdoor launcher (TAG-179)
SHA-108570471f39bb6725f07b8cddbea99ed48c22686Backdoor launcher (TAG-179)
SHA-123f4766c011d193f076dfc735dc460e2a41ead79Backdoor launcher (TAG-179)
SHA-123f6781919a50b118d8d4e6a7e9ae63b71ecc885cms_plugin.exe
SHA-12bab40c55637398f0497cff9c8cbea564d595c7fLure file (TAG-179)
SHA-14039454c9189e64285e93fc075a30b93f814b5b5cms_plugin.exe
SHA-147f8cb0c2dcf62702f58cfc1603d6325755f6820Backdoor launcher (TAG-179)
SHA-1539bd79fbb684edea94eb37518134b97e94b9dd8Lure file (TAG-179)
SHA-158cb2d95063b9df807b7aa8dc106b74ce988a491cms_plugin.exe
SHA-15d60ff36ff519c2e13e7f66cfa0bb46be79592a7Backdoor (TAG-179)
SHA-163b88d00331de88af696dfb7a896935d830e485fBackdoor (TAG-179)
SHA-16fe2e74d009abbd56de01fd7404a1245e9b47c79Lure file (TAG-179)
SHA-171757adba833b46f961e840d0f055bcce0b529c4Lure file (TAG-179)
SHA-18c329db96e093fa25268e078405a33c518dbb5c9Backdoor (TAG-179)
SHA-1c6c197e61079a0a33108c2c87b5e3c7056a138ecLure file (TAG-179)
SHA-1d66ab0cd2e44dc8389c111b7ed34c7bcb0b35311Backdoor (TAG-179)
IP142.171.183[.]8Cobalt Strike C2 server
IP172.111.233[.]105PlugX C2 server
IP172.111.233[.]12PlugX C2 server
IP172.111.233[.]26PlugX C2 server
IP172.111.233[.]36PlugX C2 server
IP172.111.233[.]96PlugX C2 server
IP172.94.9[.]19PlugX C2 server
IP172.94.9[.]43PlugX C2 server
IP172.94.9[.]49PlugX C2 server
IP193.42.25[.]65Cobalt Strike C2 server
IP41.216.188[.]140AsyncRAT C2 server
IP45.125.32[.]218ShadowPad C2 server
IP45.74.6[.]17PlugX C2 server
IP89.31.121[.]220Remcos C2 server
URLhttps[://]cms.balochistanpolice[.]gov[.]pk/client%20scripts/cms_plugin.exeImplant-hosting URL on the CMS portal

What remains

Solid

  • Documented C2 activity from 4 distinct clusters to Pakistani law enforcement networks (Feb 2024 – Apr 2026).
  • All clusters were active against Balochistan Police; at least three simultaneously in Oct–Nov 2024.
  • Two implant variants (cms_plugin.exe) deployed on the Balochistan Police CMS portal.
  • Chinese-speaking developer indicators in CMS implants (D:\codedome PDB prefix, pinyin terms, simplified Chinese log messages).
  • The CMS portal serves two user groups: police staff and citizens.

Interpretation

  • Primary China-nexus motive: independent assessment of threats to Chinese nationals (SentinelLABS interpretation, context-supported).
  • Primary India-nexus motive: visibility into Balochistan security in the context of the India-Pakistan rivalry (SentinelLABS interpretation).
  • Medium-confidence attribution of both Cobalt Strike servers to China-nexus actors.

Unknown

  • Whether the threat actors actually exfiltrated data from the compromised web application databases.
  • What payload the Rust stager downloaded from 193.42.25[.]65.
  • Whether the compromised FortiMail appliance was still processing email traffic at the time of intrusion.
  • How many users (police or citizens) executed cms_plugin.exe.
  • Whether the PlugX, ShadowPad, and Cobalt Strike clusters belong to the same operator or different ones.

Sources

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

SentinelLABS (Aleksandar Milenkoski, Julian-Ferdinand Vögele) · 9 iulie 2026 · Primary source

Factual basis for this page: intrusions, C2 clusters, IOCs, CMS compromise, attributions and strategic motives.

TAG-179 threat actor reporting

Recorded Future · 2025–2026 · Secondary source

Attribution of Remcos server 89.31.121[.]220 to TAG-179.

APT-C-08 (Bitter) activity reports

Qihoo 360 · 2025–2026 · Secondary source

Documentation of TAG-179 / APT-C-08 tooling and infection chains, including Remcos with the same C2 server.

Mysterious Elephant threat actor reporting

Kaspersky · 2025–2026 · Secondary source

TTP overlaps with TAG-179 / APT-C-08.

Copied to clipboard