CSIDB logo
Threat actor

Pakistan

Attribution profile

Type
Nation State
Location
Pakistan
Known incidents
1 incident
First seen
2019-10-14
Last seen
2019-10-14
Updated
2026-07-30 21:00
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is tracked under the alias “Pakistan” and has been observed conducting cyber operations against Indian targets. Public reporting links the activity to Pakistan-based entities such as the freight forwarding company Combined Freight (PVT) Limited, headquartered in Karachi, and references to the Pakistani Inter‑Services Intelligence (ISI) suggest a possible state nexus, although the sources stop short of attributing the campaigns directly to a government agency. The actor’s focus has consistently been on Indian government institutions, critical infrastructure, and defense‑related organizations, with objectives that include espionage through the theft of design documents, military plans, and personal data, as well as disruption via website defacement and information‑operations campaigns aimed at sowing confusion.

Typical tactics involve spear‑phishing emails that either contain malicious Excel files with obfuscated macros or exploit vulnerabilities in Adobe Reader to deliver payloads. The macros employ techniques such as registry hijacking of eventvwr.exe to bypass User Account Control, long sleep periods to evade sandbox analysis, and the downloading of malware like KeyBase, which logs keystrokes, captures screenshots, and harvests credentials. Infrastructure used in these operations includes compromised university sites in Indonesia to host malicious code and command‑and‑control servers located in Pakistan or Indonesia, with communications routed over HTTP to domains such as tripleshop.id. In addition to technical intrusion, the actor has supplemented cyber attacks with the spread of rumors and fake news on social media platforms to manipulate information flow during periods of heightened tension.

Notable campaigns described in the open source material include a 2019 wave of attacks that hit over ninety Indian government websites and critical systems shortly after the Pulwama suicide strike, targeting financial and power‑grid management systems while attempting to breach firewalls. A 2017 operation specifically targeted Mazagon Dock Shipbuilders Limited, a public sector undertaking responsible for building warships and submarines for the Indian Navy, using spoofed emails purporting to come from a Spanish equipment manufacturer to deliver the KeyBase malware. Earlier, in 2016, Operation C‑Major was reported as a Pakistan‑linked cyber‑espionage effort against Indian military employees, wherein spear‑phishing via Adobe Reader enabled the exfiltration of identity documents, salary and taxation data, personal photos, and confidential army tactics and training materials. These examples illustrate a pattern of targeting strategic sectors with a blend of technical subversion and information manipulation to achieve espionage and disruptive aims.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB