China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Pakistani Police Networks Breached by China and India-Linked Hackers

A recent investigation has uncovered a sophisticated cyberespionage campaign that targeted the Balochistan Police force in Pakistan, with hackers linked to both China and India quietly breaching their networks over a period of two years. The attackers gained access to sensitive data, including biometric databases, criminal case files, and personnel records.

The researchers at SentinelOne’s SentinelLabs threat intelligence unit found that the intrusions began in February 2024 and continued until April 2026. During this time, the hackers targeted several Pakistani police organizations, with Balochistan Police absorbing the bulk of the activity. The attackers used a range of malware tools, including PlugX, ShadowPad, Cobalt Strike, and Remcos, which were grouped into four clusters based on their infrastructure and code patterns.

What’s striking about this campaign is that it involves both China and India, two countries with rival interests in the region. The researchers suggest that the Chinese hackers may have been motivated by self-interest, given Beijing’s concerns over its nationals being targeted by Baloch separatist militants in Pakistan. Gaining direct access to Pakistani police data would allow Chinese officials to evaluate the threat on their own.

On the other hand, the India-linked activity is likely tied to the long-standing dispute between Islamabad and New Delhi over the issue of Balochistan. Pakistan has accused India of backing Baloch militants, which India has denied. The hackers may have been seeking to gather intelligence on Islamabad’s handling of the insurgency in order to inform Indian policy.

The researchers also discovered that malicious files were planted directly on Balochistan Police’s public Complaint Management System, a portal used by residents to file and track complaints. These fake software updates would have affected anyone using the site, including police officers and ordinary citizens.

SentinelLabs linked the intrusion to a Chinese-speaking developer based on shared code patterns and artifacts found in related malware samples. This suggests that the attackers may have been working with local partners or had access to insider knowledge of the Balochistan Police’s systems.

The implications of this campaign are significant, highlighting the need for greater cybersecurity awareness and cooperation between countries in the region. As the threat landscape continues to evolve, it’s clear that nation-state hackers will remain a major concern for governments and organizations around the world.

So what can you do to protect yourself from similar attacks? First and foremost, ensure that your organization is implementing robust security measures, including regular software updates, strong access controls, and ongoing monitoring of network activity. Additionally, stay informed about the latest threats and trends in cyberespionage, and be prepared to adapt your defenses accordingly. By staying vigilant and working together, we can better defend against these sophisticated attacks and protect our sensitive data from falling into the wrong hands.


Source: SecurityWeek — 2026-07-10