Also known as: tracked as, local, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Mustang Panda, Bronze President, Agrius, APT34
Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Tag-179, suspected to be linked with China-nexus and India-nexus cyberespionage groups, has targeted Pakistani law enforcement agencies between February 2024 and April 2026. The actor compromised network appliances and servers hosting sensitive data including criminal records and biometric information. Tools like PlugX, ShadowPad, Cobalt Strike, and Remcos were used in these attacks, likely driven by strategic interests in intelligence related to regional security.
Goals & Targeting
Tag-179 appears to target government and law enforcement sectors in Pakistan, particularly focusing on agencies like Balochistan Police. The primary motivation likely involves intelligence gathering related to security operations in strategic regions such as Balochistan. This aligns with the interests of both China and India, who may seek to influence or destabilize the region for their respective geopolitical agendas. The targeting of law enforcement and government systems suggests an intent to collect sensitive information, including biometric data and operational details, which could be used for diplomatic, espionage, or strategic advantage purposes.
Enhanced Description
Tag-179 is a cyberespionage threat actor that has been observed targeting law enforcement agencies in Pakistan, particularly the Balochistan Police. Between February 2024 and April 2026, the actor exploited vulnerabilities in government systems, focusing on network appliances and servers hosting critical web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. The actor employed a sophisticated approach by weaponizing legitimate-looking updates to the Complaint Management System, deploying custom implants that masqueraded as software updates. This tactic allowed the attackers to gain persistent access to targeted systems. The suspected China-nexus actors likely had motives tied to protecting Chinese nationals in Pakistan from separatist groups, while India's interest may stem from its adversarial relationship with Pakistan and desire for intelligence on security operations in Balochistan. The tools used in these attacks include PlugX, ShadowPad, Cobalt Strike, and Remcos, indicating a high level of technical proficiency. This targeting reflects the actor's focus on gathering sensitive information that could be leveraged for geopolitical advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Tag-179's campaign patterns include long-term intrusions into targeted systems, with a focus on data exfiltration from law enforcement databases. The actors demonstrated persistence by maintaining access to compromised networks over extended periods. Notable operations include the exploitation of Balochistan Police infrastructure and the use of custom implants to gain unauthorized access. Campaigns appear to follow geopolitical interests, with activity spikes potentially correlated with regional tensions or security incidents involving Chinese or Indian nationals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is moderate, as while specific tools and targeting patterns are identified, gaps exist in understanding the actor's full capabilities and exact motivations. Additionally, the lack of detailed campaign timelines andspecific TTPs leaves some uncertainty.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics