Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

China and India-linked threat actors target Pakistani law enforcement

A suspected China-nexus threat actor deployed a custom implant disguised as a portal update on Pakistan's Complaint Management System (CMS), part of a broader, multi-year espionage campaign targeting Pakistani law enforcement. The campaign involved four distinct threat clusters using malware families including PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, with the latter linked to an India-nexus actor. The activity, spanning from February 2024 to April 2026, compromised servers hosting critical police and citizen data, highlighting the targeting of institutions holding internal security intelligence.
Read Full Article →

Threat Intelligence China and India-linked threat actors target Pakistani law enforcement July 13, 2026 Share By SC Staff (Adobe Stock) As outlined in The Hacker News, SentinelOne cybersecurity researchers have disclosed details of sustained cyber espionage activity targeting several Pakistani law enforcement organizations. This activity, believed to be undertaken by suspected China- and India-aligned threat actors, spanned from February 2024 to April 2026. The compromised assets included servers hosting web applications that manage critical police and citizen data, such as criminal and biometric records, hotel and tenant registrations, and personnel files. A suspected China-nexus threat actor deployed a custom implant disguised as a portal update on the Complaint Management System (CMS), used by both police staff and citizens. SentinelOne identified compromised infrastructure linked to the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority. Four distinct threat clusters were observed, utilizing malware families like PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The Remcos RAT activity is associated with an India-nexus actor, while PlugX and ShadowPad are traditionally linked to Chinese state-sponsored groups. The convergence of these actors on Pakistani law enforcement highlights the high value of institutions that hold internal security information and threat intelligence to threat actors. Source: The Hacker News SC Staff Related Threat Intelligence Australian businesses targeted in global content management system exploitation campaign SC Staff July 13, 2026 The ACSC reports that malicious actors are actively scanning websites for vulnerabilities in various CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. Threat Intelligence Inmate charged with stealing seized cryptocurrency while serving prison sentence SC Staff July 10, 2026 A Bulgarian national, already serving a lengthy prison sentence for laundering millions stolen from American fraud victims, has been charged with stealing $290,000 in government-seized cryptocurrency. Threat Intelligence Suspected Chinese spies target universities with Roundcube exploit SC Staff July 9, 2026 The threat actor, tracked by Proofpoint as UNK_MassTraction, exploits CVE-2024-42009, a cross-site scripting vulnerability in Roundcube, to gain initial access. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms DNS Spoofing Deauthentication Attack Defacement Denial of Service Dictionary Attack Distributed Scans Domain Hijacking DumpSec Dumpster Diving Google Hacking You can skip this ad in 5 seconds

Share this article