'Amidst border tension, Chinese hackers targeted India’s power through malware'

Agencies
March 1, 2021

Amidst heightened border tension, Chinese hackers targeted India's power  through malware: US firm | Law-Order

Washington, Mar 1: Amidst the tense border tension between India and China, a Chinese government-linked group of hackers targeted India's critical power grid system through malware, a US company has claimed in its latest study, raising suspicion whether last year's massive power outage in Mumbai was a result of the online intrusion.

Recorded Future, a Massachusetts-based company which studies the use of the internet by state actors, in its recent report details the campaign conducted by a China-linked threat activity group RedEcho targeting the Indian power sector.

The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis.

Data sources include the Recorded Future Platform, SecurityTrails, Spur, Farsight and common open-source tools and techniques, the report said.

On October 12, a grid failure in Mumbai resulted in massive power outages, stopping trains on tracks, hampering those working from home amidst the COVID-19 pandemic and hitting the stuttering economic activity hard.

It took two hours for the power supply to resume for essential services, prompting Chief Minister Uddhav Thackeray to order an enquiry into the incident.

In its report, Recorded Future notified the appropriate Indian government departments prior to publication of the suspected intrusions to support incident response and remediation investigations within the impacted organisations.

There was no immediate response from the Indian government on the study by the US company.

Since early 2020, Recorded Future's Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organisations from the Chinese state-sponsored group.

The New York Times, in a report, said that the discovery raises the question about whether the Mumbai outage was meant as a message from Beijing about what might happen if India pushed its border claims too vigorously.

According to the Recorded Future report, from mid-2020 onwards, Recorded Future's midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India's power sector.

Ten distinct Indian power sector organisations, including four of the five Regional Load Despatch Centres (RLDC) responsible for operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India's critical infrastructure.

Other targets identified included two Indian seaports, it said.

According to the report, the targeting of Indian critical infrastructure offers limited economic espionage opportunities.

However, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives, it said.

Pre-positioning on energy assets may support several potential outcomes, including geostrategic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation, Recorded Future said.

RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups, it said.

The high concentration of IPs (Internet Protocols) resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicate a targeted campaign, with little evidence of wider targeting in Recorded Future's network telemetry, it said.

Recorded Future said that in the lead-up to the May 2020 border skirmishes, it observed a noticeable increase in the provisioning of PlugX malware C2 infrastructure, much of which was subsequently used in intrusion activity targeting Indian organisations.

The PlugX activity included the targeting of multiple Indian government, public sector and defence organisations from at least May 2020, it said.

While not unique to Chinese cyber espionage activity, PlugX has been heavily used by China-nexus groups for many years.

Throughout the remainder of 2020, we identified a heavy focus on the targeting of Indian government and private sector organisations by multiple Chinese state-sponsored threat activity groups, it said.

In its report, Recorder Future alleged that it also observed the suspected Indian state-sponsored group Sidewinder target Chinese military and government entities in 2020, in activity overlapping with recent Trend Micro research.

The Massachusetts-based company's report came as the armies of the two countries began disengagement of troops locked in over eight-month-long standoff in eastern Ladakh.

Both countries reached a mutual agreement last month for the disengagement of troops from the most contentious area of North and South banks of the Pangong Lake.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 4,2025

indigoflight.jpg

Domestic carrier IndiGo has cancelled over 180 flights from three major airports — Mumbai, Delhi and Bengaluru — on Thursday, December 4, as the airline struggles to secure the required crew to operate its flights in the wake of new flight-duty and rest-period norms for pilots.

While the number of cancellations at Mumbai airport stands at 86 (41 arrivals and 45 departures) for the day, at Bengaluru, 73 flights have been cancelled, including 41 arrivals, according to a PTI report that quoted sources.

"IndiGo cancelled over 180 flights on Thursday at three airports-Mumbai, Delhi and Bengaluru," the source told the news agency.

Besides, it had cancelled as many as 33 flights at Delhi airport for Thursday, the source said, adding, "The number of cancellations is expected to be higher by the end of the day."

The Gurugram-based airline's On-Time Performance (OTP) nosedived to 19.7 per cent at six key airports — Delhi, Mumbai, Chennai, Kolkata, Bengaluru and Hyderabad — on December 3, as it struggled to get the required crew to operate its services, down from almost half of December 2, when it was 35 per cent.

"IndiGo has been facing acute crew shortage since the implementation of the second phase of the FDTL (Flight Duty Time Limitations) norms, leading to cancellations and huge delays in its operations across the airports," a source had told PTI on Wednesday.

Chaos continued at several major airports for the third day on Thursday because of the cancellations.

A spokesperson for the Kempegowda International Airport (KIA) in Bengaluru said that 73 IndiGo flights had been cancelled on Thursday.

At least 150 flights were cancelled and dozens of others delayed on Wednesday, airport sources said, leaving thousands of travellers stranded, according to news agency Reuters.

The Directorate General of Civil Aviation (DGCA) has said it is investigating IndiGo flight disruptions and has asked the airline to submit the reasons for the current situation, as well as its plans to reduce flight cancellations and delays.

It may be mentioned here that the pilots' body, Federation of Indian Pilots (FIP), has alleged that IndiGo, despite getting a two-year preparatory window before the full implementation of new flight duty and rest period norms for cockpit crew, "inexplicably" adopted a "hiring freeze".

The FIP said it has urged the safety regulator, the DGCA, not to approve airlines' seasonal flight schedules unless they have adequate staff to operate their services "safely and reliably" in accordance with the New Flight Duty Time Limitations (FDTL) norms.

In a letter to the DGCA late on Wednesday, the FIP urged the DGCA to consider re-evaluating and reallocating slots to other airlines, which have the capacity to operate them without disruption during the peak holiday and fog season if IndiGo continues to "fail in delivering on its commitments to passengers due to its own avoidable staffing shortages."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 24,2025

lebanon.jpg

Israel has launched a new act of aggression on a residential neighborhood in Lebanon's capital, Beirut, killing and injuring about two dozen civilians.

The Israeli regime's military said in a statement that its forces carried out a so-called precise strike in a residential apartment in Dahiyeh in the southern suburbs of Beirut on Sunday.

The aggression targeted residential areas, killing at least five people and injuring more than 28 people, Lebanon's Health Ministry said. 

Hezbollah announced the martyrdom of senior Hezbollah commander Haytham Ali Tabatabai and four resistance fighters.

Lebanese President Michel Aoun condemned the airstrike, calling it a clear demonstration of Tel Aviv’s disregard for repeated international calls to halt violations on Lebanese soil.

“Israel refuses to implement international resolutions and all efforts aimed at ending the escalation and restoring stability,” Aoun said, urging the international community to take action to prevent further aggression.

The Palestinian Islamic Jihad movement also condemned the attack, holding the international community accountable. 

“The international community bears responsibility and continues to provide cover for these attacks as long as it does not restrain the occupiers,” said Ali Abu Shahin, a member of the group’s political bureau.

Israeli prime minister Benjamin Netanyahu’s office announced that the Israeli army carried out a strike “in the heart of Beirut."

Netanyahu reportedly approved the operation following recommendations from top Israeli security officials.

Two senior US officials commented on the Israeli strike.

The first official said that Israel did not notify Americans in advance about the attack. "We were informed immediately after the strike was carried out."

The second senior official said that the "US knew for several days that Israel was planning to escalate its strikes in Lebanon, but did not know in advance the timing, location, or target of the strike."

Speaking from the site of the Israeli strike, Lebanese MP Ali Ammar condemned the attack as part of a broader campaign of aggression that has targeted "all of Lebanon since the Washington-sponsored ceasefire."

He stated that "any attack on Lebanon is a violation of red lines; this aggression is part and parcel of the entity that targets Lebanon's dignity, sovereignty, and security of citizens."

Ammar went on to say the resistance is responding with "utmost wisdom, patience, and will confront the enemy at the appropriate time."

"Unfortunately, the enemy is emboldened to commit its aggression by voices within Lebanon that have turned themselves into tools that support its aggression," he added.

The Israeli attack on the southern suburbs of the Lebanese capital is the latest blatant violation of the ceasefire Israel signed with Hezbollah in November 2024, which was intended to end hostilities that had escalated into full-scale war.

An Israeli strike on the Ain al-Hilweh camp near Sidon in southern Lebanon late Tuesday killed at least 14 people. It wounded several others, including young students, according to the Lebanese health ministry.

The military claimed the attack targeted “a Hamas training compound” used to plan and carry out attacks against the regime -- a claim that has frequently been made without evidence.

Hamas rejected the allegations as “a blatant lie aimed at justifying the massacre,” stating it had “no military installations in the Palestinian camps in Lebanon” and that the targeted site was merely “an open sports field.”

According to Lebanese authorities, Israeli attacks have killed approximately 4,000 people and displaced more than 1.2 million residents across the country since October 2023.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 21,2025

Tejas.jpg

An Indian Air Force (IAF) Tejas fighter jet crashed on Friday, November 21, afternoon during its aerial demonstration at the Dubai Air Show, plunging to the ground at around 2:10 pm local time while performing a manoeuvre before thousands of spectators.

The IAF confirmed the incident, stating that a Tejas aircraft participating in the show had crashed and that further details were being gathered. An Air Force spokesperson said more information would be shared after initial assessments.

The crash sent thick black smoke billowing into the sky near the airport, causing panic among visitors, including families and children who had gathered to watch the display. Authorities have not yet confirmed whether the pilot managed to eject before the aircraft went down. Emergency response teams rushed to the scene, and officials have not released information on casualties or damage so far.

The Tejas is a 4.5-generation, multi-role fighter aircraft developed indigenously by Hindustan Aeronautics Limited (HAL). Designed for versatility, it is capable of offensive air support, close combat, ground attack missions and maritime operations. The aircraft family includes single-seat fighters and twin-seat trainers for both the Air Force and Navy.

HAL describes the latest version, the LCA Mk1A, as the most advanced in the series, featuring an AESA radar, an upgraded electronic warfare suite with radar-warning and self-protection jamming, smart multifunction displays, a digital map generator, a combined interrogator–transponder system and a modern radio altimeter. These enhancements significantly improve the aircraft’s combat capability and survivability.

Further updates from IAF and UAE authorities are awaited.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.