Security News > 2021 > March > Malware attack that crippled Mumbai's power system came from China, claims infosec intel outfit Recorded Future

Security intelligence firm Recorded Future's Insikt Group has written a paper alleging China was behind attacks on India's electricity grid.
The attack is considered the probable source of Mumbai's power outage in October of the same year.
"Using a combination of proactive adversary infrastructure detections, domain analysis, and Recorded Future Network Traffic Analysis, we have determined that a subset of these AXIOMATICASYMPTOTE servers share some common infrastructure tactics, techniques, and procedures with several previously reported Chinese state-sponsored groups, including APT41 and Tonto Team," the Recorded Future report said.
The firm said most of the malware was not activated and the associated power outage was the result of a subset of the payload. Recorded Future did not have access to India's power system code to analyse in further detail.
Recorded Future hypothesised that last year's power outages in Mumbai, which caused mass chaos in the city's infrastructure - ranging from trains to hospitals to financial centre operations - were a "Show of force" designed to warn India of China's capabilities.
Union power minister RK Singh did concede that a software nasty got into India's northern and southern region load dispatch centers, though the impact was limited, we're told.
News URL
Related news
- China names alleged US snoops over Asian Winter Games attacks (source)
- Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoader (source)
- New Android malware steals your credit cards for NFC relay attacks (source)
- Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery (source)
- SuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay Attacks (source)
- SK Telecom warns customer USIM data exposed in malware attack (source)
- DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks (source)
- Malware Attack Targets World Uyghur Congress Leaders via Trojanized UyghurEdit++ Tool (source)
- China is using AI to sharpen every link in its attack chain, FBI warns (source)
- Nebulous Mantis Targets NATO-Linked Entities with Multi-Stage Malware Attacks (source)