New research from SentinelOne reveals that hackers linked to China and India spent more than two years quietly infiltrating law enforcement networks in Pakistan, with the Balochistan Police coming under attack from both sides. The revelation highlights the complexity and tension of geopolitical relations in the region, as well as the importance of cybersecurity in modern international relations.

According to the SentinelLabs , the intrusions spanned two years, from February 2024 to April 2026, and targeted several Pakistani police organizations, with the Balochistan Police absorbing the bulk of the activity. The hackers managed to gain access to servers connected to biometric, criminal case files, personnel records, and citizen-facing systems.
This access to such sensitive data highlights the vulnerability of law enforcement systems and the potential consequences for national security.
The researchers grouped the intrusions into four categories based on the malware and infrastructure involved: PlugX, ShadowPad, Cobalt Strike, and Remcos. PlugX and ShadowPad are well-known tools often used by cyberespionage groups linked to China, while Cobalt Strike is a commercial tool used for pen testing and by malicious actors.
See also: Huawei's latest series has a new Made-in-China chip built in
Remcos, on the other hand, is associated with a single tracked actor, suggesting a more targeted approach. The researchers warned that categories based on shared or commercial malware may involve more than one operator, making detection and attribution of attacks particularly difficult.
Attacks from China on Pakistan
What stands out is the presence of Chinese-linked cyberspies within a police force belonging to one of Beijing’s closest regional partners. In particular, Chinese nationals working on Belt and Road Initiative in Pakistan have been repeatedly targeted in attacks linked to Balochistan separatist militants, and Chinese officials have openly criticized Islamabad’s ability to protect them.
Direct access to Pakistani police data would allow Beijing to assess the threat on its own, offering a more immediate and independent assessment of the security situation.
See also: Industrial & Commercial Bank of China (ICBC): “Hit” by ransomware

Attacks from India
On the other hand, the India -linked activity aligns with a dispute that Islamabad and New Delhi have had for years. Pakistan has long accused India of supporting Baloch militants, something India has denied, and New Delhi has its own vested interest in what the Balochistan Police networks reveal about Islamabad's handling of this insurgency.
Access to such information could provide New Delhi with valuable insights into Pakistan's strategies and weaknesses in the region.
Researchers also found malicious files disguised as software updates that were placed directly on the Balochistan Police’s public Grievance Management System, the portal that residents use to file and track complaints. The fake update notification would have affected anyone using the site, including officers and ordinary citizens.
See also: China Southern: Tickets sold at $1.30 due to technical failure
This tactic shows the sophistication and intelligence of the attacks, as it exploits users' trust in official sources.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
SentinelLabs linked the intrusion to a Chinese-speaking programmer based on common code patterns and artifacts found in related malware samples. This connection provides a more specific direction for investigations, but also a reminder of the complexity of attributing responsibility for cyberattacks, as hackers often use techniques to cover their tracks or distract investigations.

The case highlights in the most characteristic way that cyberespionage has now become a key tool for exerting geopolitical influence. Cyberattacks are no longer limited to data theft or economic exploitation, but are used to gather strategic information, monitor state organizations and gain advantage in areas where the interests of different countries clash. At the same time, the use of known malware tools and the attempt to hide the real identity of the perpetrators make it increasingly difficult to safely attribute responsibility.
For law enforcement agencies and public organizations in general, the incident is yet another reminder that protecting information infrastructure must be a constant priority. Strengthening threat detection mechanisms, regular security audits and promptly addressing potential breaches are now essential prerequisites for securing sensitive data. As state-sponsored cyber espionage groups continuously evolve their techniques, cybersecurity is becoming a critical factor not only for protecting digital systems, but also for maintaining national security and international stability.
