One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
ID: 271fbbd8-8b55-5684-a388-8c33258e0444
STIX ID: report--271fbbd8-8b55-5684-a388-8c33258e0444
Date Published: 2026-07-09
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski & Julian-Ferdinand Vögele
**Executive summary:** SentinelLabs documents sustained, multi-year cyberespionage targeting Pakistani law enforcement (especially Balochistan Police) from 2024–2026 by suspected China- and India-aligned actors using PlugX, ShadowPad, Cobalt Strike, and Remcos; attackers compromised network appliances and web applications (notably the Complaint Management System), deployed cms_plugin.exe stagers (Rust and .NET) and AsyncRAT, and exposed broad operational, biometric, and citizen-facing data—report includes IoCs and developer-attribution indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
