'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

Udupi: The Tourism Department is planning a major eco-friendly development initiative for Kamini Island, located near the Blue Flag-certified Padubidri End Point beach, aiming to attract more visitors while maintaining environmental sustainability.

Assistant Director Kumar CU emphasized that, given the island’s proximity to the Blue Flag beach, all development efforts will center around eco-friendly practices. “We are looking to enhance the Kamini River and the island’s surroundings by adding a hanging bridge, nature trails, and eco-friendly food courts offering traditional cuisine. Visitors will also be able to reach the island by pedal boats or kayaking,” he said.

The development project is estimated to cost between Rs 3 crore and Rs 4 crore. Meanwhile, the Blue Flag beach, Padubidri, continues to see a steady flow of visitors. Vijay Shetty, manager of the beach, shared that tenders for food courts and water sports have been awarded to private parties. Recently, three new coracles have been introduced, which are proving to be a hit with visitors. Additionally, three more shelters are expected to be ready by November 20.

Shetty mentioned that the beach can now accommodate between 2,500 and 3,000 visitors daily, although footfall remains lower than other district beaches due to user fees and activity restrictions. “Initially, most visitors were from Mangaluru, but now nearly 40% come from other districts, showing a shift in the visitor demographics,” Shetty noted.

To further boost tourism and promote a healthy lifestyle, a Beach Carnival is set to take place on November 23-24, featuring the National Sea Swimming Championship and a sea marathon in collaboration with the Padubidri JCI, which is celebrating its golden jubilee. Cultural events will be held at the main beach, with some sports events taking place at the Blue Flag beach. Emphasis will be placed on making all activities environmentally friendly.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

udupistatue.jpg

Udupi, Nov 11: The Karkala town police in Udupi have arrested Krishna Naik, the sculptor responsible for installing a 33-foot Parashurama statue at Umikkal Hill in Bailur, Karkala taluk. 

Naik, the owner of Krish Art World and a resident of Bengaluru's Visvesvaraya Layout, was apprehended in Mahe, part of the Union Territory of Puducherry, for allegedly substituting a look-alike statue in place of a genuine bronze figure at the Parashurama Theme Park in Karkala.

Udupi Superintendent of Police Dr. Arun K confirmed the arrest, stating that Naik faces charges under Sections 420 (cheating) and 409 (criminal breach of trust) of the Indian Penal Code. 

This legal action followed a complaint lodged in June by Krishna Shetty, a resident of Nallur village, Karkala. Shetty claimed that Naik had received a payment of ₹1,25,50,000 from Udupi Nirmithi Kendra for the installation of a bronze Parashurama statue. However, Naik allegedly deceived the government by installing a replica instead.

The statue was unveiled on January 27, 2023, by then Chief Minister Basavaraj Bommai. Current Chief Minister Siddaramaiah has since ordered a CID investigation to probe deeper into the alleged fraud surrounding the statue's installation at the theme park.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 13,2024

voting.jpg

Bengaluru: An estimated overall 10.14 per cent voter turnout was recorded during the first two hours, since the voting began for bypolls to three Assembly segments in Karnataka on Wednesday, election officials said.

The voting began at 7 am and will go on till 6 pm.

More than seven lakh voters are eligible to cast their votes in about 770 polling stations in Shiggaon, Sandur and Channapatna, where a total of 45 candidates are in the fray.

While Channapatna recorded 10.34 per cent voter turnout till 9 am, it was 10.08 per cent in Shiggaon, and 9.99 per cent in Sandur, election officials said.

Voters, including women and elderly were seen queuing up in front of polling booths in these segments.

By-polls for Sandur, Shiggaon, and Channapatna are necessitated, as the seats fell vacant following the election of their respective representatives -- E Tukaram of Congress, former CM Basavaraj Bommai of BJP, and Union Minister H D Kumaraswamy of JD(S) -- to Lok Sabha in May elections.

As many as 31 candidates are in the fray from Channapatna, while Sandur and Shiggaon have six and eight contenders, respectively.

Elaborate security arrangements have been made in the three segments for the smooth conduct of the polls.

The by-polls will witness a straight fight between the ruling Congress and BJP in Sandur and Shiggaon segments, while in Channapatna, JD(S) which is part of the NDA alliance is in contest against the grand old party.

Among the three segments, Channapatna is considered to be a "high profile", where the contest is between C P Yogeeshwara, a five time MLA from the segment and former Minister, who joined the Congress quitting BJP ahead of nomination, and actor-turned -politician Nikhil Kumaraswamy, who is Kumaraswamy’s son and former PM H D Deve Gowda's grandson.

BJP's Bharath Bommai, son of Basavaraj Bommai, is fighting Congress Yasir Ahmed Khan Pathan, who had faced defeat against the former Chief Minister in the 2023 Assembly polls, in Shiggaon.

Bharath Bommai and his father cast their vote at a polling booth in Shiggaon segment.

In Sandur, Bellary MP Tukaram's wife E Annapurna of Congress is contesting from the seat vacated by her husband, against, BJP ST Morcha president Bangaru Hanumanthu, who is considered close to party leader and former mining barron G Janardhan Reddy.

Annapurna, Tukaram and other family members cast their votes at a booth in the segment.

With Nikhil Kumaraswamy and Bharath Bommai contesting, the third generation of Gowda and Bommai families are in the fray in this by-poll. Both their fathers and grandfathers have served as Karnataka's Chief Ministers in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.