Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
ID: b3c93166-4438-56a1-a384-c2ff22aa8548
STIX ID: report--b3c93166-4438-56a1-a384-c2ff22aa8548
Feed Name: The Hacker News
SentinelOne researchers attribute a prolonged cyber-espionage campaign (Feb 2024–Apr 2026) targeting multiple Pakistani law enforcement organizations to both China- and India-aligned threat actors. Attackers compromised network appliances, FortiMail, and web applications (notably cms.balochistanpolice.gov.pk), deploying multiple malware families—PlugX, ShadowPad, Cobalt Strike, and Remcos—and uploading implants (a Rust stager fetching payloads from 193.42.25.65 and a .NET loader masquerading as 360Safe.exe implementing an AsyncRAT client), exposing citizen and personnel data and demonstrating geopolitical-motivated intelligence collection across the region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
