
highState Cyber Warfare
China-Linked Espionage Campaign Compromises Pakistani Law Enforcement and Biometric Databases
SentinelLabs has exposed a sustained espionage operation targeting Pakistani law enforcement, utilizing ShadowPad and custom implants to exfiltrate sensitive biometric and identity data.
12 July 2026Last updated 20 August 20265 min readSentinelLabs
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- South Asia
- Confidence:
- High Confidence
- Source:
- SentinelLabs
- Read Time:
- 5 min
Executive Summary\n\nCybersecurity researchers at SentinelLabs have identified a sophisticated and sustained cyber espionage campaign targeting multiple law enforcement organizations in Pakistan. The operations, attributed to China-nexus threat actors, have successfully compromised critical infrastructure, including servers hosting biometric data, national identity records, and criminal case files. This activity underscores a strategic interest in gathering intelligence on regional security apparatuses and citizen data. The campaign, which has been active for over two years, was revealed through forensic analysis of compromised web applications and network appliances used by agencies such as the Balochistan Police and the Punjab Safe Cities Authority.\n\n## Threat Analysis\n\nThe threat landscape in South Asia continues to be shaped by competing geopolitical interests, with cyber espionage serving as a primary tool for state-level intelligence gathering. The actors involved in this campaign demonstrate a high degree of persistence and technical capability, focusing on high-value targets within the security and law enforcement sectors. By gaining access to biometric and identity databases, the attackers obtain the ability to track individuals, monitor law enforcement activities, and potentially influence regional security dynamics. The campaign leverages a mix of custom-built implants and commodity remote access trojans (RATs) to maintain a low profile while ensuring robust data exfiltration capabilities.\n\n## Technical Details\n\nThe attackers primarily targeted network appliances and web applications that manage police and citizen data. A key component of the operation involved the compromise of a web application known as the Complaint Management System (CMS). The threat actors deployed a custom implant masquerading as a portal update to gain initial access and establish persistence. Analysis identified four distinct threat clusters, each utilizing different malware families: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. ShadowPad, often considered a successor to PlugX, was frequently used for high-stakes exfiltration. The attackers also utilized side-loading techniques and abused legitimate administrative tools to blend their activity with normal network operations, successfully evading detection for extended periods.\n\n## Attribution Assessment\n\nSentinelLabs attributes this activity with moderate-to-high confidence to China-nexus threat actors. The primary evidence for this assessment includes the deployment of ShadowPad and PlugX, both of which are malware families historically and almost exclusively associated with Chinese state-sponsored groups. Furthermore, the operational patterns and the strategic nature of the targets—specifically law enforcement and biometric databases in a neighboring country—align closely with the known intelligence requirements of the People's Republic of China. A secondary cluster utilizing Remcos RAT has been linked to India-aligned interests, indicating a complex, multi-actor environment.\n\n## Implications\n\nThe compromise of biometric and criminal records represents a significant national security breach for Pakistan. Beyond the immediate loss of sensitive data, the long-term presence of state-sponsored actors in these networks suggests that the attackers could monitor ongoing investigations and identify undercover assets. This campaign also highlights the vulnerability of specialized government web applications, which often lack the rigorous security patching and monitoring found in more generalized enterprise IT environments. The regional focus of the attack underscores the use of cyber operations as a component of broader geopolitical competition in South Asia.\n\n## Recommendations\n\nLaw enforcement and government agencies are advised to conduct immediate audits of all public-facing web applications, particularly those handling identity or biometric data. Organizations should implement strict network segmentation between citizen-facing portals and internal databases. Enhancing visibility through EDR (Endpoint Detection and Response) and monitoring for unusual outbound traffic to known ShadowPad command-and-control (C2) infrastructure is critical. Additionally, agencies must adopt a secure-by-design approach for custom software development, ensuring that all portal updates are digitally signed and verified to prevent the injection of malicious implants.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room