'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 13,2024

buldozerjustice.jpg

New Delhi: The Supreme Court took a firm stance on ‘bulldozer justice’ today, affirming that the Executive cannot bypass the Judiciary and that the legal process must not prejudge the guilt of an accused. In a significant judgment, the bench led by Justices BR Gavai and KV Viswanathan set new guidelines for demolition practices, responding to petitions challenging the controversial bulldozer actions taken against individuals accused of crimes.

The rise of this practice, termed 'bulldozer justice,' has seen authorities in various states demolish what they claim to be illegal structures belonging to accused individuals. However, multiple petitions questioned the legality and fairness of this approach, bringing the matter before the court.

Justice Gavai highlighted that owning a home is a cherished goal for many families, and an essential question was whether the Executive should have the authority to strip individuals of their shelter. “In a democracy, the rule of law protects citizens from arbitrary actions by the state. The criminal justice system must not assume guilt,” stated the bench, underscoring that due process is a fundamental right under the Constitution.

On the principle of separation of powers, the bench reinforced that the Judiciary alone holds adjudicatory powers and that the Executive cannot overstep these boundaries. Justice Gavai remarked, “When the state demolishes a home purely because its resident is accused of a crime, it violates the doctrine of separation of powers.”

The court issued a strong warning about accountability, stating that public officials who misuse their power or act arbitrarily must face consequences. Justice Gavai observed that selectively demolishing one property while ignoring similar cases suggests that the aim might be to penalize rather than enforce legality. “For most citizens, a house is the product of years of labor and dreams. Taking it away must be an action of last resort, thoroughly justified,” he said.

In its directives under Article 142 of the Constitution, the Supreme Court established new demolition guidelines. These include:

Mandatory Show-Cause Notice: No demolition should occur without first issuing a show-cause notice. The person served has a minimum of 15 days or the duration stated in local laws to respond.

Transparency of Notice Content: The notice must include specifics about the alleged unauthorized construction, the nature of the violation, and the rationale for demolition.

Hearing and Final Order: Authorities are required to hear the response of the affected individual before issuing a final order. The homeowner will have 15 days to address the issue, with demolition proceeding only if no stay order is obtained from an appellate authority.

Contempt Proceedings: Any breach of these guidelines would lead to contempt proceedings. Officials who disregard these norms will be personally accountable for restitution, with costs deducted from their salaries.

Additionally, the court mandated that all municipal bodies establish digital portals within three months, displaying show-cause notices and final orders on unauthorized structures to ensure public transparency and accountability.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 21,2024

modiadani.jpg

After the US prosecutors charged Gautam Adani with bribery and fraud, Congress reiterated its call for a Joint Parliamentary Committee (JPC) probe into the transactions of the Adani group, and hit out at Prime Minister Narendra Modi, alleging an "internal nexus" between him and "his favourite businessman."

Senior Congress leader Jairam Ramesh said the indictment of Gautam Adani and others by the US Securities and Exchange Commission validates his party’s call for a Joint Parliamentary Committee investigation.

The Congress has been pushing for the probe since January 2023, raising concerns over alleged irregularities involving Adani and his business dealings, said Ramesh.

Ramesh referred to the party’s “Hum Adani ke Hain” series, where 100 questions were raised about the alleged scams and the links between Prime Minister Narendra Modi and Gautam Adani.
He noted that the questions remain unanswered, reiterating the need for accountability in the matter.

The US prosecutors have charged Adani with deceiving investors by concealing information about his firm's solar energy project in India, which allegedly involved bribery.

Adani has been charged with securities fraud and conspiracy, according to an indictment unsealed on Wednesday. The case focusses on an agreement between Adani Green Energy Ltd. and another organisation to supply 12 gigawatts of solar power to the Indian government.

'BETRAYAL OF INDIAN INVESTORS'

Congress leader Pawan Khera described the allegations against Gautam Adani and his conglomerate as a “betrayal of Indian investors.”

Taking to X, Khera outlined the US charges, including claims that Adani’s group bribed Indian government officials between 2020 and 2024 to secure contracts. Citing media reports, he also pointed out that Gautam Adani personally met a government official to advance the scheme.

Khera referred to a March 2024 incident where the Adani Group allegedly misled the Bombay Stock Exchange and the National Stock Exchange, calling it a “grave violation of investor trust.”

He further highlighted a March 2023 FBI raid on the premises of Sagar Adani, Gautam Adani’s nephew, where electronic devices were seized as part of the investigation.

'SEBI NOT ABLE TO PROVE ANY CHARGES AGAINST ADANI'

Shiv Sena (UBT) leader Priyanka Chaturvedi criticised central probe agencies following US charges against Gautam Adani and others in an alleged bribery case linked to solar energy contracts.

Chaturvedi raised concerns about corporate governance and regulatory oversight in the country. “They talk about corporate governance, responsibility, and accountability. The industrialists should be asked to follow the rules and regulations, but even the agencies were defending him. The SEBI has not yet been able to prove charges against him,” she said, pointing to what she viewed as failures in ensuring accountability.

'BROUGHT DISREPUTE TO INDIA'

On US charges against Gautam Adani, AAP leader Sanjay Singh called for a probe against the industrialist. He said that the probe should be conducted by an investigation agency under the Supreme Court.

"Adani Group has brought disrepute to India. This is a very serious matter. The PM of India should come forward and answer this. All the pending matters against Adani should be probed by an investigation agency under Supreme Court monitoring, and all the corruption done by him, within and outside the country, should come out before the country and action should be taken against him," he said.

BJP DFENDS

BJP IT cell chief Amit Malviya responded sharply to the Opposition’s criticism regarding allegations involving Adani Green Energy and US-based Azure Power. He pointed out that the charges in the indictment are only allegations and emphasised, “The defendants are presumed innocent unless and until proven guilty.”

Malviya argued that the crux of the case concerns agreements to supply 12 GW of power to the Solar Energy Corporation of India (SECI), contingent on SECI securing power purchase agreements with state electricity distribution companies (SDCs).

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

iranarmy.jpg

Iran’s Islamic Revolution Guards Corps (IRGC) has killed or captured 69 terrorists linked to the Israeli spy agency Mossad during a major counterterrorism drill in the country's southeast, its spokesman says.  

General Ahmad Shafaei, the spokesman for the “Martyrs of Security” drill, said Friday that a total of 23 terrorists have been killed and another 46 arrested in various clean-up operations ever since the IRGC Ground Force launched it in the Sistan and Baluchestan province on November 1.

Seven terrorists have also turned themselves in during the period.

“The undeniable fact about terrorists is that they rely on arrogant powers, particularly the intelligence service of the wicked and vicious Zionist regime," Shafaei said.

“Unfortunately, weapons and munitions at terrorists’ disposal are among the most sophisticated ones in the world. This accounts for their heavy dependence.” 

The official stated that several members of the disbanded terror teams were non-Iranian nationals, who had been hired by foreign intelligence agencies to carry out acts of sabotage and terror inside Iran.

In a most recent operation, six terrorists were arrested and four others were eliminated, three of whom were non-Iranians, he added. 

On October 26, ten members of Iran's law enforcement forces were killed in a terrorist attack in the Gohar Kuh district of Taftan in the Sistan and Baluchestan province.

The so-called Jaish al-Adl terrorist group claimed responsibility for the assault, which was one of the deadliest in the province in recent months.

The group has carried out numerous terrorist attacks in Iran, primarily in Sistan and Baluchestan.

Its tactics include the abduction of border guards as well as targeting civilians and police stations within the province to incite chaos and disorder.

In January, Iran launched a military operation during which the headquarters of the Pakistan-based terrorist group was targeted in missile strikes, destroying its infrastructure.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.