According to a study published Wednesday by threat intelligence firm Recorded Future Inc., suspected state-sponsored Chinese hackers have targeted India’s electricity sector in recent months as part of an apparent cyber-espionage campaign.
According to the report, the hackers targeted at least seven “load dispatch” facilities in northern India, which are responsible for performing real-time grid control and electricity dispersal in the areas where they are located, near the disputed India-China border in Ladakh. Another hacking group, RedEcho, previously targeted one of the load dispatch centres, which Recorded Future claims has “significant overlaps” with a hacking group linked to the Chinese government.
According to Recorded Future, the hacker organisation TAG-38 employed a type of malicious software called ShadowPad, which was previously linked to China’s People’s Liberation Army and the Ministry of State Security
. The technique the attackers used to make the attacks — employing hijacked internet of things devices and cameras — was unusual, according to Jonathan Condra, a senior manager at Recorded Future. South Korean and Taiwanese devices were used to launch the breaches, he claimed.
By press time, the Chinese Ministry of Foreign Affairs had not responded to a request for comment. Beijing has denied any involvement in hostile cyber operations on several occasions. A request for feedback from the Indian government was likewise ignored.





