Indian power grid reportedly hit by Chinese cyberattacks

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

Chinese state-sponsored threat actors are engaged in a long-term cyberattack against India’s powerline operators, cybersecurity researchers are claiming.

Experts from Insikt Group discovered that seven Indian State Load Dispatch Centers (SLDC), that maintain the power grid in real-time, have all been compromised with a trojan.

All of them are apparently located in Ladakh, a region administered by India as a union territory, having been disputed between China, Pakistan, and India since the end of World War II.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Chinese denials

The trojan in use is called ShadowPad, and allegedly, it’s often used by threat actors with links to China’s Ministry of State Security. According to the researchers, the group behind the attack is known as Threat Activity Group 38. They managed to compromise internet-connected endpoints such as IP cameras, thanks to default login credentials which were most likely left unattended.

"The group likely compromised and co-opted internet-facing DVR/IP camera devices for command and control (C2) of ShadowPad malware infections, as well as use of the open source tool FastReverseProxy (FRP)," opined Insikt Group in its report.

The attackers’ intention wasn’t to destroy the infrastructure, at least not yet. Rather, they were more interested in intelligence gathering and cyber-espionage. That’s one of the reasons, it seems, why they were able to maintain their presence without being seen for so long.

The Chinese denied any involvement. Speaking to The Register, Chinese foreign spokesperson Zhao Lijian said the country keeps to the letter of the law and “firmly opposes” all forms of cyberattacks. One should be "all the more prudent when associating cyberattacks with the government of a certain country," he was cited saying.

Researchers from Insikt added that besides grid assets, the attackers impacted a national emergency response team, as well as a subsidiary of a logistics company.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Chinese hackers develop effective new hacking technique to go after business networks
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
China US flags cropped
Guam's critical infrastructure is under attack - and Volt Typhoon is the top suspect
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over