ATT&CKCampaignsIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions

C0043

Campaign, Jan 2021 to Apr 2022.View on attack.mitre.org

About this campaign

Indian Critical Infrastructure Intrusions is a sequence of intrusions from 2021 through early 2022 linked to People’s Republic of China (PRC) threat actors, particularly RedEcho and Threat Activity Group 38 (TAG38). The intrusions appear focused on IT system breach in Indian electric utility entities and logistics firms, as well as potentially managed service providers operating within India. Although focused on OT-operating entities, there is no evidence this campaign was able to progress beyond IT breach and information gathering to OT environment access.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1071.001
Web Protocols

During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports.

T1568
Dynamic Resolution

During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1571
Non-Standard Port

During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication.

T1573.002
Asymmetric Cryptography

During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication.

T1583.001
Domains

During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.

T1584
Compromise Infrastructure

Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity.

T1588.004
Digital Certificates

Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft.

T1599
Network Boundary Bridging

Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software2

References2

  1. RecordedFuture RedEcho 2021 Open source
    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.
  2. RecordedFuture RedEcho 2022 Open source
    Recorded Future Insikt Group. (2022, April 6). Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group. Retrieved November 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.