• हिन्दी
  • ગુજરાતી
  • বাংলা
  • తెలుగు
  • मराठी
  • ಕನ್ನಡ
  • money9
  • Insurance
  • Saving
  • Loan
  • Mutual Funds
  • Investment
  • Breaking Briefs
downloadDownload The App
Close
  • Home
  • Videos
  • Podcast
  • Banking
  • Bulletin
  • Gold
  • Healthcare
  • Real Estate
  • Tax
  • Travel
  • Breaking Briefs
  • Insurance
  • Savings
  • Loan
  • Crypto
  • Investment
  • Mutual Funds
  • Real Estate
  • Tax
  • Exclusive
  • Home / Exclusive }

Chinese hackers may be behind last year’s power outage in Mumbai: US firm

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector

  • Press Trust of India
  • Last Updated : March 1, 2021, 16:58 IST
  • Follow
Chinese hackers may be behind last year's power outage in Mumbai: US firm
Representative Image (Pixabay)
  • Follow

Washington: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India’s critical power grid system through malware, a US company has said in its latest study, raising suspicion whether last year’s massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future’s Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

In response to the allegation, Chinese Foreign Ministry spokesman Wang Wenbin on Monday rejected the criticism about China’s involvement in the hacking of India’s power grid, saying it is “irresponsible and ill-intentioned” to make allegations without proof.

“China is a staunch upholder of cybersecurity. We firmly oppose and fight any kind of cyber-attacks,” he said, replying to a question on the report of the cyber-attack on the Indian power grid. It is hard to track the origin of the cyber-attacks. You cannot make wanton guesses or smear a specific country without any proof. This is irresponsible and ill-intentioned. China firmly opposes such behaviour,” he said in Beijing.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India’s critical infrastructure.

Other targets identified included two Indian seaports, it said, adding the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

“However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives.

“Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation,” it said. RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

“The high concentration of IPs resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future’s network telemetry,” it said.

Recorded Future said in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

“The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020,” it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

“Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups,” it said.

Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company’s report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Published March 1, 2021, 16:58 IST

Download Money9 App for the latest updates on Personal Finance.

  • China
  • cyber espionage
  • India-China clash

Related

  • Corporate participation in NPS at 12-month high: NSO
  • What’s happening on India’s employment front?
  • Frequent train traveller? Rules you need to know
  • No credit card? Pay shopping EMIs via debit cards
  • Investing in Inflation: How to Grow Your Wealth Amidst Economic Challenges
  • Indians saving more in physical assets than financial: FinMin, SBI

Latest

  • 1. How Amazon, Flipkart use dark patterns to lure you!
  • 2. Don't Get Swamped By This!
  • 3. How can you find whether you have malware in your device?
  • 4. This Deed Can Give Peace of Mind!
  • 5. How much overvalued is Nifty right now?

Trending 9

  • e-gaming companies might face tax demand of Rs 1.5 lakh crore
    1 e-gaming companies might face tax demand of Rs 1.5 lakh crore
    The total tax demand on e-gaming companies might climb to a height of Rs 1.5 lakh crore, claimed a report in the Business Standard.
    Tax
    alternate

    Read

  • 2How multicap is different from multi-asset allocation fund
    Investment
    read_icon

    Read

  • 3How to prepare portfolio of F&B shares during festive season
    Stocks
    read_icon

    Read

  • 4How should you utilise bonus of your participating insurance policy?
    Insurance
    read_icon

    Read

  • 5Investment Reflections from Lord Ganesha
    Investment
    read_icon

    Read

  • 6Premium listing of EMS
    Exclusive
    read_icon

    Read

  • 7What is the ideal way to ensure children don’t get into property dispute!
    Property
    read_icon

    Read

  • 8Govt bonds in JP Morgan’s bond index could also support Indian currency
    Economy
    read_icon

    Read

  • 9What’s happening on India’s employment front?
    Exclusive
    read_icon

    Read

Exclusive

Identify your risk through a risk-o-meter, but don't make it the sole criterion
Identify your risk through a risk-o-meter, but don’t make it the sole criterion
Mutual Funds
read_icon

Read

No credit card? Pay shopping EMIs via debit cards
Exclusive
read_icon

Read

Investing in Inflation: How to Grow Your Wealth Amidst Economic Challenges
Exclusive
read_icon

Read

Frequent train traveller? Rules you need to know
Exclusive
read_icon

Read

The dark alleys on online shopping!
Cyber security
read_icon

Read

  • Trending Stories

  • How should you utilise bonus of your participating insurance policy?
  • Corporate participation in NPS at 12-month high: NSO
  • e-gaming companies might face tax demand of Rs 1.5 lakh crore
  • Govt securities of 50-year tenure highlight in borrowing target of FinMin in H2 of FY24
  • Identify your risk through a risk-o-meter, but don’t make it the sole criterion
  • TV9 Sites

  • TV9 Hindi
  • TV9Telugu.com
  • TV9 Marathi
  • TV9 Gujarati
  • TV9 Kannada
  • TV9 Bangla
  • News9 Live
  • Trends9
  • Money9 Sites

  • Money9 Hindi
  • Money9 English
  • Money9 Marathi
  • Money9 Telugu
  • Money9 Gujarati
  • Money9 Kannada
  • Money9 Bangla
  • Topics

  • Insurance
  • Savings
  • Loan
  • Stocks
  • Mutual Funds
  • Real Estate
  • Tax
  • Crypto
  • Exclusive
  • Follow us

  • FaceBook
  • Twitter
  • Youtube
  • Instagram
  • Linkedin
  • Download App

  • play_store
  • App_store
  • Contact Us
  • About Us
  • Advertise With Us
  • Privacy & Cookies Notice
  • Complaint Redressal
  • Copyright © 2023 Money9. All rights reserved.
  • share
  • Facebook
  • Twitter
  • Whatsapp
  • LinkedIn
  • Telegram
close