'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

birensingh.jpg

The Manipur Kuki MLAs have released a statement calling out Solicitor General Tushar Mehta's 'lies' in the Supreme Court. In a joint statement, the MLAs, including those from the Bharatiya Janata Party, said they had not had any meeting with the Chief Minister since May 3, 2023, nor did they intend to meet him in the future as “he was the mastermind behind the violence”.

As per the MLAs, the SG lied about state CM N Biren Singh speaking to Kuki MLAs to control the situation there, in order to halt a Supreme Court probe into the leaked tapes which allege that Singh has been complicit in the violence that broke out between Kukis and Meitis there.

"We...clarify that we have never had any meeting with Chief Minister, Shri N. Biren Singh since May 3, 2023, nor have any intention to meet him in future as he is the mastermind behind the violence and ethnic cleansing of our people from the Imphal valley, which is continuing till today, the latest being the brutal killing and burning of Mrs Zosangkim Hmar on November 7, 2024," the letter read, while condemning the recent 'barbaric' killing of the woman there, and noting the SG's assertion is 'tantamount' to misleading the top court.

“We, the undersigned ten MLAs, have come to know that during the Supreme Court hearing held on November 8, 2024, the Solicitor General of India submitted that ‘CM is meeting all Kuki MLAs and trying to bring the situation down to get peace’. In this connection, we hereby categorically state that this submission is a blatant lie and tantamount to misleading the Hon’ble Supreme Court of India,” the statement said.

The Supreme Court, while hearing a petition by a Kuki organisation, asked that it submit audio tapes to substantiate its claim that the Chief Minister was instrumental in inciting and organising violence in the northeastern State.

Solicitor-General Tushar Mehta orally informed the court that the Chief Minister was meeting all the Kuki-Zo MLAs and that peace in the State had come at a huge cost.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

amitshah.jpg

Union minister Amit Shah on Friday, November 15, said PM Narendra Modi will amend the Waqf Act despite opposition from leaders like Uddhav Thackeray and Sharad Pawar.

"Modi ji wants to change the Waqf Board law, but Uddhav ji, Sharad Pawar and Supriya Sule are opposing it," Shah said, addressing a rally at Umarkhed in Maharashtra's Yavatmal district.

"Uddhav ji, listen carefully, you all can protest as much as you want, but Modi ji will amend the Waqf Act," he said. Shah said there are two camps in the November 20 Maharashtra assembly polls, one of 'Pandavas' represented by the BJP-led Mahayuti and the other of 'Kauravas' represented by Maha Vikas Aghadi.

"Uddhav Thackeray claims that his Shiv Sena is the real one. Can the real Shiv Sena go against renaming Aurangabad to Sambhajinagar? Can the real Shiv Sena go against renaming Ahmednagar to Ahilyanagar? The real Shiv Sena stands with the BJP," Shah said.

"Rahul Baba used to say that his government would credit money in the accounts of the people instantly. You were unable to fulfil your promises in Himachal, Karnataka, and Telangana," he said.

Shah said the Mahayuti alliance has promised that women will get Rs 2,100 per month under the Ladki Bahin Yojana. "Kashmir is an integral part of India and no power in the world can snatch it away from us," Shah said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 21,2024

CAKhaleel.jpg

Prominent NRI community leader SM Syed Khalilur Rehman, fondly known as CA Khalil, passed away in Dubai on Thursday at the age of 86 after a brief illness.

Khalil had been admitted to Aster Hospital in Mankhool on Tuesday after experiencing severe leg weakness. Despite the best efforts of the medical team, he succumbed to a double heart attack that worsened his condition, his son Rais Ahmed confirmed.

The news of his passing has sent waves of grief across communities, particularly in his hometown of Bhatkal, Karnataka, where he was a celebrated figure. Tributes have been pouring in on social media, highlighting his significant contributions to international trade, social service, and education.

A Legacy of Leadership and Service

A chartered accountant by profession, Khalil was a founding member of the Dubai chapter of the Institute of Chartered Accountants of India (ICAI), where he served as chairman from 1987 to 1994. His illustrious career included key leadership roles, such as general manager of Khaleej Times, group executive director of the Ilyas and Mustafa Galadari Group, and vice-chairman of the Jashanmal Group of Companies.

He also chaired Maadhyama Communications and Sahil Online, a web-based news platform, and was a director and trustee of several media companies and charitable organisations in Dubai and India.

A Champion for Education and Philanthropy

Khalil’s impact extended far beyond his professional achievements. As president and general secretary of Anjuman Hami-e-Muslimeen, he played a pivotal role in the development of educational institutions, including schools and colleges in Bhatkal and surrounding areas. His dedication to social upliftment earned him recognition from the Government of Karnataka, which honoured him with a prestigious award for his philanthropic contributions.

A Life Celebrated

The Bhatkal Muslim Khaleej Council (BMKC) recently released a documentary celebrating Khalil’s remarkable life and service to the community—a testament to his enduring legacy.

CA Khalil is survived by his family and countless admirers across the globe. His passing marks the end of an era for Indian expatriates in the UAE and beyond, leaving behind a legacy of leadership, generosity, and commitment to community service.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.