'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 24,2025

lebanon.jpg

Israel has launched a new act of aggression on a residential neighborhood in Lebanon's capital, Beirut, killing and injuring about two dozen civilians.

The Israeli regime's military said in a statement that its forces carried out a so-called precise strike in a residential apartment in Dahiyeh in the southern suburbs of Beirut on Sunday.

The aggression targeted residential areas, killing at least five people and injuring more than 28 people, Lebanon's Health Ministry said. 

Hezbollah announced the martyrdom of senior Hezbollah commander Haytham Ali Tabatabai and four resistance fighters.

Lebanese President Michel Aoun condemned the airstrike, calling it a clear demonstration of Tel Aviv’s disregard for repeated international calls to halt violations on Lebanese soil.

“Israel refuses to implement international resolutions and all efforts aimed at ending the escalation and restoring stability,” Aoun said, urging the international community to take action to prevent further aggression.

The Palestinian Islamic Jihad movement also condemned the attack, holding the international community accountable. 

“The international community bears responsibility and continues to provide cover for these attacks as long as it does not restrain the occupiers,” said Ali Abu Shahin, a member of the group’s political bureau.

Israeli prime minister Benjamin Netanyahu’s office announced that the Israeli army carried out a strike “in the heart of Beirut."

Netanyahu reportedly approved the operation following recommendations from top Israeli security officials.

Two senior US officials commented on the Israeli strike.

The first official said that Israel did not notify Americans in advance about the attack. "We were informed immediately after the strike was carried out."

The second senior official said that the "US knew for several days that Israel was planning to escalate its strikes in Lebanon, but did not know in advance the timing, location, or target of the strike."

Speaking from the site of the Israeli strike, Lebanese MP Ali Ammar condemned the attack as part of a broader campaign of aggression that has targeted "all of Lebanon since the Washington-sponsored ceasefire."

He stated that "any attack on Lebanon is a violation of red lines; this aggression is part and parcel of the entity that targets Lebanon's dignity, sovereignty, and security of citizens."

Ammar went on to say the resistance is responding with "utmost wisdom, patience, and will confront the enemy at the appropriate time."

"Unfortunately, the enemy is emboldened to commit its aggression by voices within Lebanon that have turned themselves into tools that support its aggression," he added.

The Israeli attack on the southern suburbs of the Lebanese capital is the latest blatant violation of the ceasefire Israel signed with Hezbollah in November 2024, which was intended to end hostilities that had escalated into full-scale war.

An Israeli strike on the Ain al-Hilweh camp near Sidon in southern Lebanon late Tuesday killed at least 14 people. It wounded several others, including young students, according to the Lebanese health ministry.

The military claimed the attack targeted “a Hamas training compound” used to plan and carry out attacks against the regime -- a claim that has frequently been made without evidence.

Hamas rejected the allegations as “a blatant lie aimed at justifying the massacre,” stating it had “no military installations in the Palestinian camps in Lebanon” and that the targeted site was merely “an open sports field.”

According to Lebanese authorities, Israeli attacks have killed approximately 4,000 people and displaced more than 1.2 million residents across the country since October 2023.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 24,2025

israelsyra.jpg

Israeli forces have pushed over the Syrian frontier, erecting a checkpoint and stopping vehicles in the southwestern city of Quneitra, in yet another breach of the Arab country’s sovereignty.

The violation took place on Sunday, when the troops made their way across the border, setting up the outpost near the Ain al-Bayda junction in northern Quneitra, Syrian outlets reported.

According to the al-Ikhbariya paper, an Israeli detachment positioned itself at the junction, halting cars and conducting searches.

The Syrian Arab News Agency (SANA) reported that three Israeli military vehicles then moved further into the northern countryside, deploying between the town of Jubata al-Khashab and the villages of Ofaniya and Ain al-Bayda. The agency added that a separate Israeli unit mounted a new incursion in the central region, approaching the villages of Umm Batina and al-Ajraf.

Residents said such activities have surged in recent months, pointing to Israeli advances onto farmland, leveling of extensive forested areas, arrests, and spread of mobile checkpoints.

The Israeli regime began markedly increasing its military aggression against Syria last year.

The escalation coincided with increasingly ferocious onslaughts throughout the country by the so-called Hay'at Tahrir al-Sham (HTS) Takfiri terrorist group, which the government of President Bashar al-Assad had confined to northwestern Syria. The HTS, however, managed to overthrow the government as the Israeli attacks would pummel the country’s civilian and defensive infrastructure.

Various reports have shown that, during the escalation, the regime conducted more than 1,000 airstrikes on the Syrian territory and over 400 ground raids into the south.

Following the collapse of the Assad government, Tel Aviv also widened its grip over the occupied Golan Heights by taking control of a demilitarized buffer zone, in defiance of a 1974 Disengagement Agreement. Earlier this month, senior Israeli officials, including Prime Minister Benjamin Netanyahu, visited the buffer zone, prompting expressions of alarm on the part of the United Nations.

The United States, the regime’s biggest ally, has, meanwhile, been fraternizing the HTS head Abu Mohammed al-Jolani amid the widely reported prospect of rapprochement with Tel Aviv.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 27,2025

siddDKS.jpg

Congress president Mallikarjun Kharge on Thursday announced that he will convene a high-level meeting in New Delhi with senior leaders — including Rahul Gandhi, Karnataka Chief Minister Siddaramaiah and Deputy Chief Minister D.K. Shivakumar — to resolve the escalating leadership turmoil in Karnataka and “put an end to the confusion.”

Kharge said the discussions would focus on the way forward for the ruling party, as rumours of a possible leadership change continue to swirl. The speculation has intensified after the Congress government crossed the halfway mark of its five-year term on November 20, reviving talk of an alleged 2023 “power-sharing agreement” between Siddaramaiah and Shivakumar.

“After reaching Delhi, I will call three or four important leaders and hold discussions. Once we talk, we will decide how to move ahead and end this confusion,” Kharge told reporters in Bengaluru, according to PTI.

When asked specifically about calling Siddaramaiah and Shivakumar to Delhi, he responded: “Certainly, we should call them. We will discuss with them and settle the issue.”

He confirmed that Rahul Gandhi, the Chief Minister, the Deputy Chief Minister and other senior members would be part of the deliberations. “After discussing with everyone, a decision will be made,” he said.

Meanwhile, Siddaramaiah held a separate strategy meeting at his Bengaluru residence with ministers and leaders seen as his close confidants, including G. Parameshwara, Satish Jarkiholi, H.C. Mahadevappa, K. Venkatesh and K.N. Rajanna.
Signalling calm, the Chief Minister told reporters, “Will go to Delhi if the high command calls.”

Shivakumar echoed a similar stance, saying he too would head to the national capital if summoned by the party leadership.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.