'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 13,2024

voting.jpg

Bengaluru: An estimated overall 10.14 per cent voter turnout was recorded during the first two hours, since the voting began for bypolls to three Assembly segments in Karnataka on Wednesday, election officials said.

The voting began at 7 am and will go on till 6 pm.

More than seven lakh voters are eligible to cast their votes in about 770 polling stations in Shiggaon, Sandur and Channapatna, where a total of 45 candidates are in the fray.

While Channapatna recorded 10.34 per cent voter turnout till 9 am, it was 10.08 per cent in Shiggaon, and 9.99 per cent in Sandur, election officials said.

Voters, including women and elderly were seen queuing up in front of polling booths in these segments.

By-polls for Sandur, Shiggaon, and Channapatna are necessitated, as the seats fell vacant following the election of their respective representatives -- E Tukaram of Congress, former CM Basavaraj Bommai of BJP, and Union Minister H D Kumaraswamy of JD(S) -- to Lok Sabha in May elections.

As many as 31 candidates are in the fray from Channapatna, while Sandur and Shiggaon have six and eight contenders, respectively.

Elaborate security arrangements have been made in the three segments for the smooth conduct of the polls.

The by-polls will witness a straight fight between the ruling Congress and BJP in Sandur and Shiggaon segments, while in Channapatna, JD(S) which is part of the NDA alliance is in contest against the grand old party.

Among the three segments, Channapatna is considered to be a "high profile", where the contest is between C P Yogeeshwara, a five time MLA from the segment and former Minister, who joined the Congress quitting BJP ahead of nomination, and actor-turned -politician Nikhil Kumaraswamy, who is Kumaraswamy’s son and former PM H D Deve Gowda's grandson.

BJP's Bharath Bommai, son of Basavaraj Bommai, is fighting Congress Yasir Ahmed Khan Pathan, who had faced defeat against the former Chief Minister in the 2023 Assembly polls, in Shiggaon.

Bharath Bommai and his father cast their vote at a polling booth in Shiggaon segment.

In Sandur, Bellary MP Tukaram's wife E Annapurna of Congress is contesting from the seat vacated by her husband, against, BJP ST Morcha president Bangaru Hanumanthu, who is considered close to party leader and former mining barron G Janardhan Reddy.

Annapurna, Tukaram and other family members cast their votes at a booth in the segment.

With Nikhil Kumaraswamy and Bharath Bommai contesting, the third generation of Gowda and Bommai families are in the fray in this by-poll. Both their fathers and grandfathers have served as Karnataka's Chief Ministers in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 12,2024

lebanon.jpg

The UN humanitarian coordinator for Lebanon has warned that the “picture of life in Lebanon remains grim,” highlighting an "alarming" level of human suffering and significant humanitarian consequences due to the ongoing Israeli carnage.

Imran Riza, the UN Deputy Special Coordinator and Resident and Humanitarian Coordinator for Lebanon (UNSCOL), provided a stark overview of the Arab country's dire circumstances in a statement released on Monday.

“The current picture of life in Lebanon remains grim. Yesterday, airstrikes reportedly killed 23 people, including seven children, in the village of Aalmat in Mount Lebanon,” Riza said on X.

An airstrike in the city of Tyre on the same day resulted in the tragic deaths of five siblings from a single family, all of whom had special needs, according to his statement.

He added that in the last week, Israeli airstrikes have killed at least 241 individuals and left 642 others injured in Lebanon, as reported by the Ministry of Health.

“In the past month, more than 185,000 people have fled their homes in their search for safety within the country, bringing the total to over 870,000 people internally displaced,” Riza said

The UN official highlighted that numerous individuals, including the elderly and those with health issues, are staying behind while witnessing the ruins of their ancestral homes.

He urged for the swift safeguarding of civilian people and infrastructure, emphasizing the necessity to uphold international humanitarian law and end the ongoing violence.

Lebanon’s National News Agency reported that Israeli forces bombed a house in the town of Maydoun in Bekaa on Monday night, killing three people and destroying the house.

Earlier, Israel bombed the northern town of Ain Yaaqoub, killing at least 14 people.

The killings came as Israeli military continued to pound Lebanon, bombing shops selling electrical appliances in the southern city of Tyre and carrying out air raids on the towns of Shamshtar in eastern Baalbek and Roumine in southern Nabatieh.

Lebanon’s Ministry of Health said Israeli attacks killed at least 54 people across the country on Monday.

Israel’s merciless attacks continue despite calls from the UN Security Council for an immediate ceasefire and directives from the International Court of Justice urging measures to prevent genocide and alleviate the dire humanitarian situation in Gaza and Lebanon.

In Lebanon, at least 3,243 people have been killed and 14,134 others wounded in Israeli attacks since the war on Gaza began on October 7, 2023.

The Lebanese resistance movement Hezbollah opened a support front for Palestinians in Gaza only a day after the Israeli regime unleashed its genocidal war on the besieged territory.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 12,2024

HDKzameer.jpg

Mysuru, Nov 12: Zameer Ahmad Khan, the Tourism and Waqf minister of Karnataka, who stirred a controversy by addressing the Union Minister HD Kumaraswamy as ‘Kaala Kumaraswamy’ has tendered apologies for his remarks.

Speaking to reporters in Mysuru on Tuesday, Minister Zameer stated that he will apologise if remarks have hurt JD-S workers.

“We both are very close. Then, in a total of 24 hours, we were together for 14 hours. He used to fondly address me as “kulla” (shorty) and I used to address him as “kariyanna” (blacky, kaalia),” Minister Zameer stated.

“I am not addressing him as ‘kaalia’ for the first time. I have not said something highly derogatory. It is being made as big in the backdrop of elections. With love, he used to call me a shorty and I called him a blacky. If I had caused pain to anyone by my words I apologise,” he said.

He further stated: “Kumaraswamy had said that he didn’t want the votes of the Muslim community. But now they are attempting to purchase Muslim votes. Against this backdrop, I have made the remark.”

Minister for Home G. Parameshwara stated on Tuesday, “Minister Zameer and Kumaraswamy are close friends. Their comments against each other are not significant.”

Zameer Ahmad Khan, the Tourism and Waqf minister of Karnataka stirred a controversy on Monday as he addressed the Union Minister as ‘Kaala Kumaraswamy’.

JD-S on Tuesday demanded a public apology and resignation of Minister for Waqf and Tourism Zameer Ahmad Khan over his ‘racist’ remarks.

“Remember, there is no place here for your divisive policies. You have insulted the people by making ethnic, racist and discriminatory statements. You should apologize to the people of the state and resign,” the JD (S) demanded in the post.

Union Parliamentary Affairs and Minister for Minority Affairs Kiren Rijiju reacted sternly to the racist jibe and stated, “I strongly deplore Congress Minister Zameer Ahmed calling Union Minister and former Chief Minister of Karnataka Kumaraswamy as 'Kaalia Kumaraswamy'.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.