Indian power grid reportedly hit by Chinese cyberattacks

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

Chinese state-sponsored threat actors are engaged in a long-term cyberattack against India’s powerline operators, cybersecurity researchers are claiming.

Experts from Insikt Group discovered that seven Indian State Load Dispatch Centers (SLDC), that maintain the power grid in real-time, have all been compromised with a trojan.

All of them are apparently located in Ladakh, a region administered by India as a union territory, having been disputed between China, Pakistan, and India since the end of World War II.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Chinese denials

The trojan in use is called ShadowPad, and allegedly, it’s often used by threat actors with links to China’s Ministry of State Security. According to the researchers, the group behind the attack is known as Threat Activity Group 38. They managed to compromise internet-connected endpoints such as IP cameras, thanks to default login credentials which were most likely left unattended.

"The group likely compromised and co-opted internet-facing DVR/IP camera devices for command and control (C2) of ShadowPad malware infections, as well as use of the open source tool FastReverseProxy (FRP)," opined Insikt Group in its report.

The attackers’ intention wasn’t to destroy the infrastructure, at least not yet. Rather, they were more interested in intelligence gathering and cyber-espionage. That’s one of the reasons, it seems, why they were able to maintain their presence without being seen for so long.

The Chinese denied any involvement. Speaking to The Register, Chinese foreign spokesperson Zhao Lijian said the country keeps to the letter of the law and “firmly opposes” all forms of cyberattacks. One should be "all the more prudent when associating cyberattacks with the government of a certain country," he was cited saying.

Researchers from Insikt added that besides grid assets, the attackers impacted a national emergency response team, as well as a subsidiary of a logistics company.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Chinese hackers develop effective new hacking technique to go after business networks
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
China US flags cropped
Guam's critical infrastructure is under attack - and Volt Typhoon is the top suspect
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts&#039; web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all