Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors tag-179

Also known as: tracked as, local, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Mustang Panda, Bronze President, Agrius, APT34

Description

Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Critical infrastructure
Information technology
Energy
Healthcare
Manufacturing
Non profit
Hospitality
Education
Transportation
Aviation
Maritime
Food agriculture
Construction
Media
Think tank
Gaming

Targeted Countries / Regions

Pakistan
CN
IN
PK
AE
TW
VN
US
UA
RU
JP
IR
PL
KR
MX
BY
CA
KP
SG
RO
NL
IT

AI Analysis

· 1 week ago

Executive Summary

Tag-179, suspected to be linked with China-nexus and India-nexus cyberespionage groups, has targeted Pakistani law enforcement agencies between February 2024 and April 2026. The actor compromised network appliances and servers hosting sensitive data including criminal records and biometric information. Tools like PlugX, ShadowPad, Cobalt Strike, and Remcos were used in these attacks, likely driven by strategic interests in intelligence related to regional security.

Goals & Targeting

Tag-179 appears to target government and law enforcement sectors in Pakistan, particularly focusing on agencies like Balochistan Police. The primary motivation likely involves intelligence gathering related to security operations in strategic regions such as Balochistan. This aligns with the interests of both China and India, who may seek to influence or destabilize the region for their respective geopolitical agendas. The targeting of law enforcement and government systems suggests an intent to collect sensitive information, including biometric data and operational details, which could be used for diplomatic, espionage, or strategic advantage purposes.

Enhanced Description

Tag-179 is a cyberespionage threat actor that has been observed targeting law enforcement agencies in Pakistan, particularly the Balochistan Police. Between February 2024 and April 2026, the actor exploited vulnerabilities in government systems, focusing on network appliances and servers hosting critical web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. The actor employed a sophisticated approach by weaponizing legitimate-looking updates to the Complaint Management System, deploying custom implants that masqueraded as software updates. This tactic allowed the attackers to gain persistent access to targeted systems. The suspected China-nexus actors likely had motives tied to protecting Chinese nationals in Pakistan from separatist groups, while India's interest may stem from its adversarial relationship with Pakistan and desire for intelligence on security operations in Balochistan. The tools used in these attacks include PlugX, ShadowPad, Cobalt Strike, and Remcos, indicating a high level of technical proficiency. This targeting reflects the actor's focus on gathering sensitive information that could be leveraged for geopolitical advantage.

Key Capabilities

  • C2 infrastructure deployment
  • Custom implant development
  • Spear-phishing campaigns
  • Exploitation of web application vulnerabilities
  • Persistence techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1059.003
T1055
T1078
T1566.001

Software / Tooling

PlugX
ShadowPad
Cobalt Strike
Remcos

Campaigns & Victims

Tag-179's campaign patterns include long-term intrusions into targeted systems, with a focus on data exfiltration from law enforcement databases. The actors demonstrated persistence by maintaining access to compromised networks over extended periods. Notable operations include the exploitation of Balochistan Police infrastructure and the use of custom implants to gain unauthorized access. Campaigns appear to follow geopolitical interests, with activity spikes potentially correlated with regional tensions or security incidents involving Chinese or Indian nationals.

IOC Patterns

  • Spear-phishing emails targeting law enforcement personnel
  • Custom malware implants masquerading as software updates
  • C2 communication via domain generation algorithms (DGA)
  • Web application vulnerabilities exploitation

Recommended Actions

  • Patches and updates for web applications managing sensitive data must be applied promptly.
  • Implement network monitoring for unusual traffic patterns indicative of C2 activity.
  • Enhance email security to detect and block spear-phishing attempts.
  • Conduct regular training sessions for law enforcement personnel on threat recognition.

Suggested Tags

APT
espionage
government-targeted
China-nexus
India-nexus

Confidence Assessment

Confidence in the data is moderate, as while specific tools and targeting patterns are identified, gaps exist in understanding the actor's full capabilities and exact motivations. Additionally, the lack of detailed campaign timelines andspecific TTPs leaves some uncertainty.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 13 Domain 4 IPv4 Address 1 SHA-256 Hash 2

References

  1. attack.mitre.org — Cited by web research for: local
  2. attack.mitre.org — Cited by web research for: Tech Sectors
  3. www.trendmicro.com — Cited by web research for: Mustang Panda
  4. www.sentinelone.com — Cited by web research for: PlugX
  5. www.recordedfuture.com — Cited by web research for: GolangGhost
  6. unit42.paloaltonetworks.com — Cited by web research for: CVE-2019-9081

Intel Summary

34

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Backdoor / C2
espionage
government-targeted
China-nexus
India-nexus

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.