BANGKOK: India's power sector has been targeted by hackers in a long-term operation thought to have been carried out by a state-sponsored Chinese group, a U.S.-based private cybersecurity company detailed in a new report. Over the last several months, the Insikt Group, the threat research division of Massachusetts-based Recorded Future, said it has collected evidence that hackers targeted seven Indian state centres responsible for carrying out electrical dispatch and grid control near a border area disputed by the two nuclear neighbours.
The group primarily used the trojan ShadowPad, which is believed to have been developed by contractors for China's Ministry of State Security, leading to the conclusion that this was a state-sponsored hacking effort, the group reported. "ShadowPad continues to be employed by an ever-increasing number of People's Liberation Army and Ministry of State Security-linked groups, with its origins linked to known MSS contractors first using the tool in their own operations and later likely acting as a digital quartermaster," Recorded Future said in the report late Wednesday.
China's Foreign Ministry spokesman Zhao Lijian said Thursday the report had been "noted" by Beijing, but that China "firmly opposes and combats any form of cyberattacks, and will not encourage, support or condone any cyberattacks." "I would like to advise the company concerned that if they really care about global cybersecurity, they should pay more attention to the cyberattacks by the U.S. government hackers on China and other countries, and do more to help promote dialogue and cooperation among countries, instead of using the cyberattack issue to stir up trouble and throw mud at China," he told reporters.
Indian External Affairs Ministry spokesperson Arindam Bagchi said India hasn't discussed the issue with China. "We have seen reports. There is a mechanism to safeguard our critical infrastructure to keep it resilient. We haven't raised this issue with China," he said. Indian Minister of Power R.K. Singh said the report was not a cause for concern. "We are always prepared," he said. "We have a very robust security system. We are always alert."
Insikt Group already detected and reported a suspected Chinese-sponsored hack of 10 Indian power sector organizations in February 2021 by a group known as RedEcho. The more recent hack "displays targeting and capability consistencies" with RedEcho, but there are also "notable distinctions" between the two so the group has been given the working name of Threat Activity Group 38, or TAG-38, as more information is gathered.