China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms ("One Target, Two Flags")

China-Nexus and India-Nexus Espionage Groups Converge on (TL-2026-2343), also tracked as One Target, Two Flags, is a high-severity advanced persistent threat campaign, first published 2026-09-05. It is attributed to ShadowPad (China, India) with medium confidence, affects Balochistan Police Complaint Management System (CMS), maps to 12 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-2343

Threat ID
TL-2026-2343
Also known as
One Target, Two Flags
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-05
Last reviewed
2026-09-05
Attribution
ShadowPad
Attribution confidence
MEDIUM
Nation-state nexus
China, India
Motivation
ESPIONAGE
Target sectors
government administration, police - law enforcement, public-safety
Target regions
pakistan, South Asia
Detection rules
9
Indicators of compromise
33

Malware and tooling in China-Nexus and India-Nexus Espionage Groups Converge on

Malware and tooling: AsyncRAT, Cobalt Strike, PlugX, Remcos, ShadowPad, Cobalt Strike, Remcos, ShadowPad

SentinelOne Labs documents two independent, unrelated cyberespionage campaigns converging on Pakistani law enforcement between February 2024 and April 2026: China-nexus clusters deploying PlugX, ShadowPad, and Cobalt Strike, and the India-nexus actor TAG-179 (Mysterious Elephant / APT-C-08 / Bitter) deploying Remcos, both targeting Balochistan Police's Complaint Management System (CMS) and related digitalization infrastructure.

How China-Nexus and India-Nexus Espionage Groups Converge on works

SentinelOne Labs' "One Target: China, India Espionage Converge on Pakistani Law Enforcement" (published 2026-07-09) documents sustained, independently operated cyberespionage activity by China-nexus and India-nexus actors against Pakistani law enforcement digitalization platforms, primarily the Balochistan Police. Rather than a single coordinated campaign, the report identifies four distinct, temporally bounded malware clusters converging on the same victim set: a PlugX cluster (27 Feb 2024 - 28 Sep 2024), a ShadowPad cluster (5 Nov 2024 - 29 Nov 2024), and a Cobalt Strike cluster (12 Oct 2024 - 5 Dec 2025) attributed with medium confidence to China-nexus operators, plus a Remcos-based campaign (13 Jan 2026 - 9 Apr 2026) attributed to the India-nexus actor TAG-179 (tracked by Recorded Future, overlapping with Kaspersky's 'Mysterious Elephant' and Qihoo 360's APT-C-08/Bitter).

The China-nexus operators are assessed to be independently validating physical/operational security for Chinese nationals and interests in Balochistan against separatist threats (notably Baloch Liberation Army-aligned militancy), rather than acting on behalf of, or coordinating with, Pakistani state security services. Their principal foothold was the Balochistan Police Complaint Management System (CMS) at cms.balochistanpolice.gov.pk: two `cms_plugin.exe` implant variants were staged in the web-accessible `/client scripts/` directory and served to CMS visitors via a fake 'Update Complete! Please refresh the page' portal-update prompt. A Rust-compiled stager variant retrieved a second-stage payload from a Cobalt Strike C2 (193.42.25.65); a .NET variant masqueraded as a Qihoo 360 security component ('360Safe.exe') and reflectively loaded an embedded AsyncRAT assembly configured to beacon to 41.216.188.140. Developer artifacts in the .NET implant -- a `D:\codedome\` build-path prefix, simplified-Chinese log strings, and the pinyin term 'xinshi' (新式, 'new variant') in a PDB path -- indicate a Chinese-speaking developer, corroborating the China-nexus attribution independent of the PlugX/ShadowPad/Cobalt Strike victimology overlap.

The India-nexus actor TAG-179/Bitter pursued a separate, later intrusion into the same CMS ecosystem using a decoy document masquerading as an internal 'operational plan for repatriation of illegal foreigners' referencing Afghan Citizen Card (ACC) holders and coordination between district police, NADRA, and Pakistani intelligence bodies -- a lure plausible enough to match genuine Balochistan law enforcement business, and consistent with Bitter's established South Asian government/foreign-affairs targeting profile and its history of RTF/phishing-delivered custom backdoors communicating over RPC. TAG-179's payload in this campaign was a Remcos RAT configured to a dedicated C2 at 89.31.121.220, active 13 Jan - 9 Apr 2026, overlapping the tail of the China-nexus Cobalt Strike cluster but with no observed coordination or infrastructure sharing between the two nation-state clusters.

Beyond Balochistan Police, SentinelOne names three additional Pakistani law-enforcement/government digitalization targets sharing the same threat model -- Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority -- though the report provides victimology naming only, without cluster-specific malware, dates, or data-exposure detail for those three. The core structural finding is that Pakistan's 'Smart Police Station' digitalization push, which unified citizen-facing and internal-operations systems (Complaint Management, First Information Report/FIR case files, HR Management Information System personnel and payroll records, Criminal Record Management System biometric fingerprint data, Anti-Vehicle Lifting System stolen-vehicle investigation data, HotelEye NADRA-linked guest logs, and the Tenant Registration System's landlord/tenant-criminal-record integration) onto a small set of internet-facing web applications, inadvertently created a single high-value espionage target whose compromise threatens both institutional operations (officer records, case files, biometric databases) and civilian safety (citizens who filed complaints or used the platforms, whose device access was exposed by the same implants).

MITRE ATT&CK techniques used in TL-2026-2343

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1620 Reflective Code Loading

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Execution

T1204.002 User Execution: Malicious File

Initial Access

T1566 Phishing

Resource Development

T1583.004 Acquire Infrastructure: Server; T1584.004 Compromise Infrastructure: Server; T1588.001 Obtain Capabilities: Malware

Affected products and versions in China-Nexus and India-Nexus Espionage Groups Converge on

  • Balochistan Police — Complaint Management System (CMS)
    Vulnerable versions: cms.balochistanpolice.gov.pk, all versions as of the Feb 2024-Apr 2026 activity window
  • Balochistan Police — First Information Report (FIR) system
    Vulnerable versions: as deployed under the Smart Police Station digitalization program
  • Balochistan Police — Human Resource Management Information System (HRMIS)
    Vulnerable versions: as deployed under the Smart Police Station digitalization program
  • Balochistan Police — Criminal Record Management System (CRMS)
    Vulnerable versions: as deployed under the Smart Police Station digitalization program
  • Balochistan Police — Anti-Vehicle Lifting System (AVLS)
    Vulnerable versions: as deployed under the Smart Police Station digitalization program
  • Balochistan Police — HotelEye guest check-in system
    Vulnerable versions: as deployed under the Smart Police Station digitalization program, NADRA-integrated
  • Balochistan Police — Tenant Registration System (TRS)
    Vulnerable versions: as deployed under the Smart Police Station digitalization program
  • Government of Pakistan — Khyber Pakhtunkhwa Police digitalization platforms
    Vulnerable versions: named as sharing the same threat model; no cluster-specific detail published
  • Government of Pakistan — Islamabad Police digitalization platforms
    Vulnerable versions: named as sharing the same threat model; no cluster-specific detail published
  • Government of Pakistan — Punjab Safe Cities Authority platforms
    Vulnerable versions: named as sharing the same threat model; no cluster-specific detail published

Remediation for China-Nexus and India-Nexus Espionage Groups Converge on

Immediate actions

  • Block all listed C2 IP addresses (172.111.233.36/.96/.12/.105/.26, 172.94.9.49/.43/.19, 45.74.6.17, 45.125.32.218, 142.171.183.8, 193.42.25.65, 89.31.121.220, 41.216.188.140) at network perimeter and DNS/egress filtering layers
  • Remove cms_plugin.exe and any 360Safe.exe-named binaries from web-accessible directories on cms.balochistanpolice.gov.pk and sibling police web applications (FIR, HRMIS, CRMS, AVLS, HotelEye, TRS)
  • Audit '/client scripts/' and equivalent web-root subdirectories on all Pakistani law-enforcement digitalization platforms for unauthorized executables masquerading as update prompts
  • Hunt for the listed SHA-1 hashes across endpoint and file-integrity monitoring for Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and Punjab Safe Cities Authority environments
  • Reset credentials and rotate session tokens for any accounts that accessed the compromised CMS portal during the identified activity windows

Workarounds

  • Disable or gate direct download of executables from citizen-facing complaint-status portals until integrity controls are in place

Longer-term hardening

  • Segment citizen-facing web applications from internal law-enforcement systems (FIR, HRMIS, CRMS) so a public-portal compromise cannot pivot to personnel or biometric databases
  • Deploy EDR with behavioral detection across all Smart Police Station digitalization infrastructure, not just internet-facing web servers
  • Establish code-signing and integrity verification for any executable served from a government web portal to prevent fake-update-prompt delivery
  • Conduct a security architecture review of the Smart Police Station digitalization program given the demonstrated value of centralized citizen+institutional data as a single collection target

Timeline of China-Nexus and India-Nexus Espionage Groups Converge on

  • China-nexus PlugX cluster activity against Pakistani law enforcement infrastructure first observed
  • PlugX cluster activity window closes
  • China-nexus Cobalt Strike cluster activity begins, overlapping the tail of the PlugX window
  • China-nexus ShadowPad cluster activity observed
  • ShadowPad cluster activity window closes
  • China-nexus Cobalt Strike cluster activity window closes
  • India-nexus TAG-179 (Bitter/Mysterious Elephant/APT-C-08) Remcos campaign against Balochistan Police begins
  • TAG-179 Remcos campaign activity window closes
  • SentinelOne Labs publishes "One Target: China, India Espionage Converge on Pakistani Law Enforcement," detailing both independent campaigns

Sources cited for China-Nexus and India-Nexus Espionage Groups Converge on

More in apt

Detection coverage for TL-2026-2343

As of 2026-09-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2343 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats