Cyberspies from China and India Caught Snooping on Pakistani Police Networks
In a shocking revelation, researchers at SentinelOne have uncovered a two-year-long cyberespionage campaign targeting Pakistani law enforcement networks, with both Chinese and Indian-linked hackers sneaking into the same police force’s systems. The Balochistan Police, which has been caught in the middle of the rivalries between these two regional powers, bore the brunt of this cyber assault.
The attackers, who used a variety of malware including PlugX, ShadowPad, Cobalt Strike, and Remcos, managed to breach servers storing sensitive information such as biometric databases, criminal case files, personnel records, and citizen-facing systems. What’s more alarming is that these hackers seemed to be motivated by self-interest rather than any altruistic goals. The Chinese-linked activity, for instance, can be linked to Beijing’s concerns about the safety of its nationals working on Belt and Road projects in Pakistan.
The presence of China-linked cyberspies inside a police force belonging to one of Beijing’s closest regional partners raises serious questions about Islamabad’s ability to protect its own citizens. Given the repeated attacks targeting Chinese nationals by Baloch separatist militants, it’s clear that Beijing has a vested interest in evaluating the threat on its own terms. By gaining direct access to Pakistani police data, China can assess the security situation and take necessary measures to safeguard its interests.
The India-linked activity, on the other hand, is believed to be linked to New Delhi’s long-standing dispute with Islamabad over the Balochistan region. Pakistan has accused India of backing Baloch militants, which India has consistently denied. Given this complex web of rivalries, it’s no surprise that Indian hackers would try to infiltrate Pakistani police networks to gather intelligence on Islamabad’s handling of the insurgency.
What’s even more disturbing is the discovery of malicious files disguised as software updates planted directly on the public Complaint Management System used by Balochistan Police. These fake update prompts could have compromised anyone using the site, including officers and ordinary citizens. SentinelLabs linked this intrusion to a Chinese-speaking developer based on shared code patterns and artifacts found in related malware samples.
This cyberespionage campaign highlights the increasingly complex nature of global cybersecurity threats. With both China and India engaging in aggressive cyber operations, it’s clear that Pakistani law enforcement networks are vulnerable to exploitation. As a result, Islamabad must take urgent steps to strengthen its digital defenses and prevent such breaches from happening in the future.
Practically speaking, this incident serves as a stark reminder of the importance of robust cybersecurity measures for all organizations, especially those handling sensitive information. Law enforcement agencies, in particular, should prioritize implementing multi-layered security protocols, conduct regular threat assessments, and engage with international partners to share intelligence on emerging threats. By doing so, they can better protect their networks from sophisticated cyber attacks and prevent the exploitation of sensitive data.
Source: SecurityWeek — 2026-07-10