'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 24,2025

lebanon.jpg

Israel has launched a new act of aggression on a residential neighborhood in Lebanon's capital, Beirut, killing and injuring about two dozen civilians.

The Israeli regime's military said in a statement that its forces carried out a so-called precise strike in a residential apartment in Dahiyeh in the southern suburbs of Beirut on Sunday.

The aggression targeted residential areas, killing at least five people and injuring more than 28 people, Lebanon's Health Ministry said. 

Hezbollah announced the martyrdom of senior Hezbollah commander Haytham Ali Tabatabai and four resistance fighters.

Lebanese President Michel Aoun condemned the airstrike, calling it a clear demonstration of Tel Aviv’s disregard for repeated international calls to halt violations on Lebanese soil.

“Israel refuses to implement international resolutions and all efforts aimed at ending the escalation and restoring stability,” Aoun said, urging the international community to take action to prevent further aggression.

The Palestinian Islamic Jihad movement also condemned the attack, holding the international community accountable. 

“The international community bears responsibility and continues to provide cover for these attacks as long as it does not restrain the occupiers,” said Ali Abu Shahin, a member of the group’s political bureau.

Israeli prime minister Benjamin Netanyahu’s office announced that the Israeli army carried out a strike “in the heart of Beirut."

Netanyahu reportedly approved the operation following recommendations from top Israeli security officials.

Two senior US officials commented on the Israeli strike.

The first official said that Israel did not notify Americans in advance about the attack. "We were informed immediately after the strike was carried out."

The second senior official said that the "US knew for several days that Israel was planning to escalate its strikes in Lebanon, but did not know in advance the timing, location, or target of the strike."

Speaking from the site of the Israeli strike, Lebanese MP Ali Ammar condemned the attack as part of a broader campaign of aggression that has targeted "all of Lebanon since the Washington-sponsored ceasefire."

He stated that "any attack on Lebanon is a violation of red lines; this aggression is part and parcel of the entity that targets Lebanon's dignity, sovereignty, and security of citizens."

Ammar went on to say the resistance is responding with "utmost wisdom, patience, and will confront the enemy at the appropriate time."

"Unfortunately, the enemy is emboldened to commit its aggression by voices within Lebanon that have turned themselves into tools that support its aggression," he added.

The Israeli attack on the southern suburbs of the Lebanese capital is the latest blatant violation of the ceasefire Israel signed with Hezbollah in November 2024, which was intended to end hostilities that had escalated into full-scale war.

An Israeli strike on the Ain al-Hilweh camp near Sidon in southern Lebanon late Tuesday killed at least 14 people. It wounded several others, including young students, according to the Lebanese health ministry.

The military claimed the attack targeted “a Hamas training compound” used to plan and carry out attacks against the regime -- a claim that has frequently been made without evidence.

Hamas rejected the allegations as “a blatant lie aimed at justifying the massacre,” stating it had “no military installations in the Palestinian camps in Lebanon” and that the targeted site was merely “an open sports field.”

According to Lebanese authorities, Israeli attacks have killed approximately 4,000 people and displaced more than 1.2 million residents across the country since October 2023.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 26,2025

students.jpg

Bengaluru, Nov 26: Karnataka is taking its first concrete steps towards lifting a three-decade-old ban on student elections in colleges and universities. Deputy Chief Minister D.K. Shivakumar announced Wednesday that the state government will form a small committee to study the reintroduction of campus polls, a practice halted in 1989 following incidents of violence.

Speaking at a 'Constitution Day' event organised by the Karnataka Congress, Mr. Shivakumar underscored the move's aim: nurturing new political leadership from the grassroots.

"Recently, (Leader of the Opposition in Lok Sabha) Rahul Gandhi wrote a letter to me and Chief Minister (Siddaramaiah) asking us to think about restarting student elections," Shivakumar stated. "I'm announcing today that we'll form a small committee and seek a report on this."

Student elections were banned in Karnataka in 1989, largely due to concerns over violence and the infiltration of political party affiliates into campus life. The ban effectively extinguished vibrant student bodies and the pipeline of young leaders they often produced.

Mr. Shivakumar, who also serves as the Karnataka Congress president, said that former student leaders will be consulted to "study the pros and cons" of the re-introduction.

Acknowledging the history of the ban, he added, "There were many criminal activities taking place back then. We’ll see how we can conduct (student) elections by regulating such criminal activities."

The Deputy CM reminisced about his own journey, which began on campus. He recalled his political activism at Sri Jagadguru Renukacharya College leading to his first Assembly ticket in 1985 at the age of 23. "That's how student leadership was at the time. Such leadership has gone today. College elections have stopped," he lamented, adding that for many, college elections were "like a big movement" where leaders were forged.

The move, driven by the Congress high command's push to cultivate young talent, will face scrutiny from academics and university authorities who have, in the past, expressed concern that the return of polls could disrupt the peaceful academic environment and turn campuses into political battlegrounds.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 27,2025

imrankhan.jpg

Authorities at Pakistan’s high-security Adiala Jail in Rawalpindi on Wednesday dismissed speculation about the condition of imprisoned former Pakistan Prime Minister Imran Khan, rejecting rumours that he had been moved out of the facility or was in danger. Officials said Khan was in “good health” and described the viral death claims as “baseless.”

“There is no truth to reports about his transfer from Adiala Jail,” the Rawalpindi prison administration said in a statement, according to Geo News. “He is fully healthy and receiving complete medical attention.”

Amid swirling rumours on social media, Imran Khan’s party, Pakistan Tehreek-e-Insaf (PTI), urged the federal government to issue an official clarification and demanded that authorities allow his family to meet him immediately, Dawn reported.

The frenzy began after Khan’s three sisters called for an impartial probe into what they described as a “brutal” police assault on them and other PTI supporters outside Adiala Jail last week. Soon after, several social media handles circulated unverified claims alleging that Khan had been “killed” inside the prison.

The rumours intensified when a handle named “Afghanistan Times” claimed that “credible sources” had confirmed Khan’s “murder” and that his body had been moved out of the jail — allegations that have not been verified by any credible agency.

Imran Khan, PTI’s patron-in-chief, has been lodged in the Rawalpindi prison since August 2023 in multiple cases. For over a month, an undeclared restriction has prevented family members and senior PTI leaders from meeting him. Khyber-Pakhtunkhwa Chief Minister Sohail Afridi has reportedly been denied access despite making seven attempts.

In a letter to Punjab Police Chief Usman Anwar, Khan’s sisters — Noreen Niazi, Aleema Khan, and Dr. Uzma Khan — said they were “peacefully protesting” outside the jail when police allegedly launched an unprovoked assault after streetlights were switched off.

“At 71, I was seized by my hair, thrown to the ground and dragged across the road,” Noreen Niazi said, alleging that other women present were also slapped and manhandled.

Adiala Jail officials reiterated that speculation over Imran Khan’s health was unfounded and insisted that his well-being was being ensured, Geo News reported.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.