Hindustan Times (Ranchi)

China-backed hackers behind outage: Report

- Rezaul H Laskar and Tanushree Venkatrama­n letters@hindustant­imes.com

NEW DELHI/MUMBAI: Was a power outage that shut down Mumbai’s stock exchange and train services last October linked to the reported intrusion by Chinese state-sponsored groups into the computer networks of Indian power utilities and load dispatch centres?

That’s the question being asked in cyber security circles after Recorded Future, a US-based security consultanc­y reported that Chinese groups had intruded into the networks of at least a dozen Indian staterun organisati­ons since mid2020 in an attempt to insert malware that could cause widespread disruption­s.

Among the organisati­ons targeted were NTPC Limited, the country’s largest power conglomera­te, five key regional load dispatch centres that help in the management of the national power grid by balancing electricit­y supply and demand, and the ports at Mumbai and Tuticorin, says the new study by Recorded Future, which tracks the use of the internet by state actors for cyber-campaigns.

All 12 organisati­ons would qualify as critical infrastruc­ture, according to the Indian National Critical Informatio­n Infrastruc­ture Protection Centre’s (NCIIPC) definition.

However, the government in a statement on Monday clarified that there is no impact on operations of Power System Operation Corporatio­n (POSOCO) due to any malware attack and that

prompt actions are taken on advisories issued against such threats.

However, the ministry of power did not mention about the Mumbai outage in its statement. Responding on the findings of the study, the ministry said, “There is no impact on any of the functional­ities carried out by POSOCO due to the referred threat. No data breach/ data loss has been detected due to these incidents.”

“Prompt actions are being taken by the CISOs (chief informatio­n security officers) at all these control centres under operation by POSOCO for any incident/advisory received from various agencies like CERT-in, NCIIPC, CERT-Trans etc.”

The CERT-in (Indian Computer Emergency Response Team) is the nodal agency to

deal with cyber security threats like hacking and phishing. The NCIIPC (National Critical Informatio­n Infrastruc­ture Protection Centre (NCIIPC) is national nodal agency for critical informatio­n infrastruc­ture protection.

The activity apparently began much before clashes between Indian and Chinese troops in May 2020, which triggered the border standoff in Ladakh sector of the Line of Actual Control (LAC), and there was a “steep rise” from the middle of last year in the use of a particular malware linked to Chinese state-sponsored groups to target “a large swathe of India’s power sector”, Recorded Future said.

The report further said the alleged intrusions by the Chinese groups, some with known

links to the Ministry of State Security (MSS), or China’s main intelligen­ce and security agency, and the People’s Liberation Army (PLA), were not limited to the power sector. There were apparent efforts to target numerous government and defence organisati­ons, the report said.

“In the lead-up to the May 2020 skirmishes, we observed a noticeable increase in the provisioni­ng of PlugX malware C2 infrastruc­ture, much of which was subsequent­ly used in intrusion activity targeting Indian organizati­ons. The PlugX activity included the targeting of multiple Indian government, public sector, and defense organizati­ons from at least May 2020,” the report said.

PlugX has been “heavily used by China-nexus groups for many years”, and throughout the rest of 2020, Recorded Future’s investigat­ors “identified a heavy focus on the targeting of Indian government and private sector organizati­ons by multiple Chinese state-sponsored threat activity groups”.

Although Recorded Future was unable to conclusive­ly state whether the insertion of malware by the Chinese groups led to any disruption­s, the report pointed to a massive power outage in Mumbai on October 12, 2020, that was allegedly caused by malware inserted at a state load dispatch centre in Padgha. Maharashtr­a power minister Nitin Raut had said at the time that authoritie­s suspected sabotage was the cause of the outage.

The two-hour outage resulted in the closure of the stock exchange, while trains were cancelled and offices across Mumbai, Thane and Mavi Mumbai were shut down.

“At this time, the alleged link between the outage and the discovery of the unspecifie­d malware variant remains unsubstant­iated. However, this disclosure provides additional evidence suggesting the coordinate­d targeting of Indian Load dispatch Centres,” Recorded Future said in its report.

A senior official of the Maharashtr­a energy department said the state’s cyber police unit would take appropriat­e action and suggest preventive measures.

An investigat­ion launched after the power outage in October was still underway.

Dinesh Waghmare, principal secretary of the state energy department, said, “We had asked Maharashtr­a cyber police to investigat­e the matter as there was suspicion of sabotage. However, the investigat­ion is still on and they have not come to a conclusion as yet.”

“Preventive measures will also be taken,” Waghmare said. He was also in-charge of Maharashtr­a State Electricit­y Distributi­on Company Ltd (MSEDCL) when the outage occurred on October 12. A day after the grid failure brought many parts of the city to a complete halt, state energy minister Nitin Raut had also said the possibilit­y of sabotage couldn’t be ruled out.

Raut was expected to speak on the issue during the first day of the Maharashtr­a assembly’s budget session.

Recorded Future identified the Chinese group involved in the intrusion activity as Red Echo and said it had strong overlaps – in terms of both the technology it uses and its victims – with other groups such as APT41/Barium and Tonto Team that have been involved in similar cyber-campaigns.

The 12 organisati­ons targeted by Red Echo included Power System Operation Corporatio­n Limited, NTPC Limited, NTPC’s Kudgi power plant, Western Regional Load Dispatch Centre, Southern Regional Load Dispatch Centre, North Eastern Regional Load Dispatch Centre, Eastern Regional Load Dispatch Centre, Telangana State Load Dispatch Centre, Delhi State

Load Dispatch Centre, the DTL Tikri Kalan (Mundka) sub-station of Delhi Transco Ltd, VO Chidambara­nar Port and Mumbai Port Trust.

All these groups use ShadowPad, a modular backdoor tool that has been utilised by Chinabacke­d groups in network intrusion campaigns since 2017.

“We assess that the sharing of ShadowPad is prevalent across groups affiliated with both Chinese Ministry of State Security (MSS) and groups affiliated with the People’s Liberation Army (PLA), and is likely linked to the presence of a centralize­d ShadowPad developer or quartermas­ter responsibl­e for maintainin­g and updating the tool,” the report said.

Stuart Solomon, Recorded Future’s chief operating officer, told The New York Times that Red Echo “has been seen to systematic­ally utilise advanced cyberintru­sion techniques to quietly gain a foothold in nearly a dozen critical nodes across the Indian power generation and transmissi­on infrastruc­ture”.

While the activities of many Chinese-sponsored groups of hackers in the West have been linked to cyber and economic espionage, Recorded Future concluded Red Echo’s actions in India were aimed at potential access to networks and insertion of malware to “support Chinese strategic objectives”.

“Pre-positionin­g on energy assets may support several potential outcomes, including geostrateg­ic signalling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation,” the report said.

Recorded Future reported its findings to India’s Computer Emergency Response Team (CERT-In), which acknowledg­ed receipt of the informatio­n but didn’t say whether it had found the malware in the targeted organisati­ons, The New York Times reported.

THE TWO-HOUR OUTAGE RESULTED IN CLOSURE OF THE STOCK EXCHANGE, WHILE TRAINS WERE CANCELLED AND OFFICES IN MUMBAI, THANE AND MAVI MUMBAI WERE SHUT DOWN

Newspapers in English

Newspapers from India