'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

amitshah.jpg

Union minister Amit Shah on Friday, November 15, said PM Narendra Modi will amend the Waqf Act despite opposition from leaders like Uddhav Thackeray and Sharad Pawar.

"Modi ji wants to change the Waqf Board law, but Uddhav ji, Sharad Pawar and Supriya Sule are opposing it," Shah said, addressing a rally at Umarkhed in Maharashtra's Yavatmal district.

"Uddhav ji, listen carefully, you all can protest as much as you want, but Modi ji will amend the Waqf Act," he said. Shah said there are two camps in the November 20 Maharashtra assembly polls, one of 'Pandavas' represented by the BJP-led Mahayuti and the other of 'Kauravas' represented by Maha Vikas Aghadi.

"Uddhav Thackeray claims that his Shiv Sena is the real one. Can the real Shiv Sena go against renaming Aurangabad to Sambhajinagar? Can the real Shiv Sena go against renaming Ahmednagar to Ahilyanagar? The real Shiv Sena stands with the BJP," Shah said.

"Rahul Baba used to say that his government would credit money in the accounts of the people instantly. You were unable to fulfil your promises in Himachal, Karnataka, and Telangana," he said.

Shah said the Mahayuti alliance has promised that women will get Rs 2,100 per month under the Ladki Bahin Yojana. "Kashmir is an integral part of India and no power in the world can snatch it away from us," Shah said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

birensingh.jpg

The Manipur Kuki MLAs have released a statement calling out Solicitor General Tushar Mehta's 'lies' in the Supreme Court. In a joint statement, the MLAs, including those from the Bharatiya Janata Party, said they had not had any meeting with the Chief Minister since May 3, 2023, nor did they intend to meet him in the future as “he was the mastermind behind the violence”.

As per the MLAs, the SG lied about state CM N Biren Singh speaking to Kuki MLAs to control the situation there, in order to halt a Supreme Court probe into the leaked tapes which allege that Singh has been complicit in the violence that broke out between Kukis and Meitis there.

"We...clarify that we have never had any meeting with Chief Minister, Shri N. Biren Singh since May 3, 2023, nor have any intention to meet him in future as he is the mastermind behind the violence and ethnic cleansing of our people from the Imphal valley, which is continuing till today, the latest being the brutal killing and burning of Mrs Zosangkim Hmar on November 7, 2024," the letter read, while condemning the recent 'barbaric' killing of the woman there, and noting the SG's assertion is 'tantamount' to misleading the top court.

“We, the undersigned ten MLAs, have come to know that during the Supreme Court hearing held on November 8, 2024, the Solicitor General of India submitted that ‘CM is meeting all Kuki MLAs and trying to bring the situation down to get peace’. In this connection, we hereby categorically state that this submission is a blatant lie and tantamount to misleading the Hon’ble Supreme Court of India,” the statement said.

The Supreme Court, while hearing a petition by a Kuki organisation, asked that it submit audio tapes to substantiate its claim that the Chief Minister was instrumental in inciting and organising violence in the northeastern State.

Solicitor-General Tushar Mehta orally informed the court that the Chief Minister was meeting all the Kuki-Zo MLAs and that peace in the State had come at a huge cost.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 12,2024

ikramuddinkamil.jpg

The Taliban regime has appointed Ikramuddin Kamil as the acting consul in the Afghan mission in Mumbai, Afghan media has reported.

It is the first such appointment made by the Taliban set up to any Afghan mission in India.

There was no immediate comment from the Indian side on the appointment that came.

The Ministry of Foreign Affairs of Afghanistan has announced the appointment of Kamil as the acting consul in Mumbai, the Taliban-controlled Bakhtar News Agency reported on Monday, citing unnamed sources.

"He is currently in Mumbai, where he is fulfilling his duties as a diplomat representing the Islamic Emirate," it said.

The appointment is part of Kabul's efforts to strengthen diplomatic ties with India and enhance its presence abroad, the media outlet said

Kamil holds a PhD degree in international law and previously served as the deputy director in the department of security cooperation and border affairs in the foreign ministry, it said.

He is expected to facilitate consular services and represent the interests of Afghanistan in India, the report added.

Kamil's appointment comes days after the external affairs ministry's point-person for Afghanistan held talks with the Taliban's acting defence minister, Mullah Mohammad Yaqoob, in Kabul.

Sher Mohammad Abbas Stanikzai, the Taliban's deputy foreign minister for political affairs, also posted on X about Kamil's appointment.

The appointment of Kamil is seen as part of efforts to facilitate consular services to the Afghan population in Mumbai.

There has been almost negligible presence of diplomatic staff at the Afghan missions in India.

Most of the diplomats appointed by the Ashraf Ghani government have already left India.

In May, Zakia Wardak, the seniormost Afghan diplomat in India, resigned from her position after reports emerged that she was caught at the Mumbai airport for allegedly trying to smuggle 25 kg of gold worth Rs 18.6 crore from Dubai.

Wardak had taken charge as the acting ambassador of Afghanistan to New Delhi late last year, after working as the Afghan consul general in Mumbai for more than two years.

She took charge of the Afghan embassy in New Delhi last November, after the mission helmed by then ambassador Farid Mamundzay announced its closure.

Mamundzay, who was an appointee of the Ghani government, had moved to the United Kingdom.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.