Chinese Hackers Attempted India’s Power Using Malware
Amidst tense India-China border tension, a group of hackers linked to the Chinese government attacked India’s critical power grid system through malware, a US company claimed in its latest study, raising suspicions of if last year’s massive power outage in Mumbai was the result. of online intrusion.
Recorded Future, a Massachusetts-based company that studies Internet use by state actors, in its recent report details the campaign carried out by RedEcho, a group of threat activities linked to China that targets the Indian energy sector. .
The activity was identified through a combination of large-scale automated network traffic analysis and expert analysis.
Data sources include Recorded Future Platform, SecurityTrails, Spur, Farsight, and common open-source tools and techniques, according to the report.
On October 12, a grid failure in Mumbai led to massive power outages, stopping trains on the tracks, hampering those working from home amid the COVID-19 pandemic, and hitting stuttering economic activity hard.
It took two hours for power supplies for essential services to resume, prompting Chief Minister Uddhav Thackeray to order an investigation into the incident.
In its report, Recorded Future notified relevant Indian government departments prior to publication of the alleged intrusions to support incident response and remediation investigations within affected organizations.
There was no immediate response from the Indian government on the study by the American company.
Since early 2020, Recorded Future’s Insikt Group observed a large increase in suspicion of intrusion activity directed against Indian organizations from the Chinese state-sponsored group.
The New York Times, in a report, said the discovery raises the question of whether the Mumbai blackout was a message from Beijing about what could happen if India pushes its border claims too hard.
According to the Recorded Future report, from mid-2020 onwards, the Recorded Future midpoint collection revealed a sharp increase in the use of tracked infrastructure such as AXIOMATICASYMPTOTE, spanning ShadowPad (C2) command and control servers, to target a large swath of the Indian energy sector.
Ten different organizations in the Indian power sector, including four of the five Regional Load Dispatch Centers (RLDCs) responsible for operating the power grid by balancing electricity supply and demand, have been identified as targets in a concerted campaign against critical infrastructure in India.
Other identified targets include two Indian seaports, he said.
According to the report, targeting critical infrastructure in India offers limited opportunities for economic espionage.
“However, we assess that they raise significant concerns about the potential pre-positioning of network access to support Chinese strategic objectives,” he said.
“Pre-positioning in energy assets can support several potential outcomes, including geostrategic signaling during intense bilateral tensions, supportive influence trades, or as a precursor to kinetic escalation,” Recorded Future said.
RedEcho has a strong infrastructure and victimology overlaps with Chinese groups APT41 / Barium and Tonto Team, while ShadowPad is used by at least five different Chinese groups, he said.
“The high concentration of IP (Internet protocols) targeting critical infrastructure entities in India communicating for several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicates a targeted campaign, with little evidence of more targeting. broad in Recorded Future’s network telemetry, “he said.
Recorded Future said that in the run-up to the May 2020 border skirmishes, it saw a notable increase in provisioning of PlugX malware’s C2 infrastructure, much of which was subsequently used in hacking activities targeting Indian organizations.
“PlugX’s activity included the targeting of multiple Indian governments, public sector, and defense organizations since at least May 2020,” he said.
While it is not unique to Chinese cyber espionage activity, PlugX has been heavily used by China nexus groups for many years.
“During the remainder of 2020, we identified a strong focus on the targeting of the Indian government and private sector organizations by multiple groups of Chinese state-sponsored threat activities,” he said.

She is a freelance blogger, writer, and speaker, and writes for various entertainment magazines.

