<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber defence | IMR</title>
	<atom:link href="https://imrmedia.in/tag/cyber-defence/feed/" rel="self" type="application/rss+xml" />
	<link>https://imrmedia.in/tag/cyber-defence/</link>
	<description>Indian Military Review, Defense News, Indian Defence Review</description>
	<lastBuildDate>Mon, 02 May 2022 07:13:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://imrmedia.in/wp-content/uploads/2020/04/cropped-IMR-Logo-512x512-px-32x32.jpg</url>
	<title>cyber defence | IMR</title>
	<link>https://imrmedia.in/tag/cyber-defence/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Event Preview: Cyber Defence India 2022</title>
		<link>https://imrmedia.in/event-preview-cyber-defence-india-2022/</link>
					<comments>https://imrmedia.in/event-preview-cyber-defence-india-2022/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Tue, 15 Mar 2022 08:36:00 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[APT41]]></category>
		<category><![CDATA[Chinese Cyber Attacks]]></category>
		<category><![CDATA[Colonial Pipeline]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber defence]]></category>
		<category><![CDATA[Cyber Defence India]]></category>
		<category><![CDATA[cyber military superiority]]></category>
		<category><![CDATA[Cyber Security Awareness]]></category>
		<category><![CDATA[Cyber Security Technologies]]></category>
		<category><![CDATA[cyber war]]></category>
		<category><![CDATA[Cyber Warfare Doctrine]]></category>
		<category><![CDATA[cyber weapons]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[DarkSide]]></category>
		<category><![CDATA[Defence Cyber Agency]]></category>
		<category><![CDATA[Military Networks]]></category>
		<category><![CDATA[Multi-Factor Authentication]]></category>
		<category><![CDATA[National Critical Info Infrastructure Protection Centre]]></category>
		<category><![CDATA[National Cyber Security Policy]]></category>
		<category><![CDATA[National Security Council]]></category>
		<category><![CDATA[National Technical Research Organisation]]></category>
		<category><![CDATA[NCIIPC]]></category>
		<category><![CDATA[NCSP]]></category>
		<category><![CDATA[NSC]]></category>
		<category><![CDATA[NTRO]]></category>
		<category><![CDATA[Operation Aurora]]></category>
		<category><![CDATA[RedEcho]]></category>
		<category><![CDATA[RedFoxtrot]]></category>
		<category><![CDATA[TAG-28]]></category>
		<category><![CDATA[Unit 69010]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=13001</guid>

					<description><![CDATA[<p>Webinar &#38; Virtual Expo, 10 June 2022 The Centre for Joint Warfare Studies (CENJOWS) and Indian Military Review will organise a Webex webinar-cum-virtual expo on &#8220;Cyber Defence India&#8221; on 10 June 2022. Background A Chinese hacking group called RedEcho is believed to have attacked Maharashtra&#8217;s electricity grid in March 2021, amidst an ongoing crisis in [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/event-preview-cyber-defence-india-2022/">Event Preview: Cyber Defence India 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-webinar-virtual-expo-10-june-2022">Webinar &amp; Virtual Expo, 10 June 2022</h2>



<p class="wp-block-paragraph">The Centre for Joint Warfare Studies (CENJOWS) and Indian Military Review will organise a Webex webinar-cum-virtual expo on &#8220;Cyber Defence India&#8221; on 10 June 2022.</p>



<h3 class="wp-block-heading">Background</h3>



<p class="wp-block-paragraph">A Chinese hacking group called RedEcho is believed to have attacked Maharashtra&#8217;s electricity grid in March 2021, amidst an ongoing crisis in Ladakh. Hackers from North Korea penetrated the Kundankulam Nuclear Power Plant (KKNPP) in 2019 in a bid to test the cyber security of the plant and steal information about the reactor design.</p>



<p class="wp-block-paragraph">In some ways, cyber war between India and China is already taking place – after India banned hundreds of Chinese mobile apps, limiting Chinese investments in the Indian economy and giving a bloody nose to the People&#8217;s Liberation Army on the Line of Actual Control on 15 June 2020.</p>



<p class="wp-block-paragraph">The primary objective is cyber military superiority to provide freedom of action in, through, and from cyberspace to support mission objectives. The corollary is to deny freedom of action to adversaries.</p>



<h3 class="wp-block-heading">Chinese Cyber Attacks</h3>



<p class="wp-block-paragraph">China has been leading a worldwide hacking and economic espionage campaign, using cyber attacks to steal intellectual property in disregard of bilateral and multilateral agreements.</p>



<p class="wp-block-paragraph">China is one of the world’s pre-eminent players using cyber weapons. Used as methods of espionage, state-sponsored data breaches and server hacks pose a significant threat to global security. China was responsible for worldwide rise of cyber crime by 600% during the Covid-19 pandemic. Even before the virus hit, China had overtaken Russia as the biggest state sponsor of cyber attacks against the West.</p>



<p class="wp-block-paragraph">Some of the Chinese cyber attacks that have made digital history in the past include:</p>



<ul class="wp-block-list"><li>Operation Aurora (Jan 2010) affected Internet Explorer, Google and Adobe.</li><li>New York Times’s reporters and employees, in Jan 2013, were attacked for four-months after it published an investigation into how relatives of the then Chinese prime minister, Wen Jiabao, accrued several billion dollars through business dealings.</li><li>The personnel files of more than 20 million people of the US Office of Personnel Management (OPM), were stolen from Nov 2013 to April 2015.</li><li>Four Chinese military hackers were indicted in 2020, for stealing data of 147 million Americans customers of credit-reporting agency Equifax.</li><li>The Vatican’s computer systems were attacked (100 cyber threats a month) by suspected state-sponsored Chinese hackers in July 2020 ahead of talks between Beijing and the Vatican about the renewal of operations of the Catholic Church in China.&nbsp;</li><li>Two Chinese hackers were indicted, on 7 July 2020, in a bid to steal data from Moderna Inc, the vaccine manufacturer. Spain complained in Sep 2021 that Chinese hackers were stealing Covid research secrets from labs.</li></ul>



<h3 class="wp-block-heading">Indian Targets</h3>



<p class="wp-block-paragraph">In March 2013, DRDO&#8217;s computers were breached by Chinese hackers, who took files related to Cabinet Committee on Security (CCS), to a server in Guangdong in China and the Indian defence ministry ordered a probe.</p>



<p class="wp-block-paragraph">China-linked hacker group, RedFoxtrot, from their intelligence Unit 69010, targeted India’s power sector, including conglomerate NTPC, in March 2021. RedFoxtrot&#8217;s predominant targets are sectors like government, defence, and telecommunications across Central Asia, India, and Pakistan.</p>



<p class="wp-block-paragraph">Some Indian targets included Walchandnagar Industries engaged in India’s Nuclear and Space programmes, and defence manufacturer Alpha Design Technologies and Bharat Sanchar Nigam Limited (BSNL).</p>



<p class="wp-block-paragraph">The Times Group (Feb, Aug 2021), Unique Identification Authority of India (UIDAI), and MP Police Department (June 2021) have been targeted by suspected Chinese state-sponsored threat activity group TAG-28, which used Winnti malware. In June 2021, APT41 was responsible for cyber attack against Air India.</p>



<h3 class="wp-block-heading">Russia-Ukraine War</h3>



<p class="wp-block-paragraph">Cyber conflicts are fought in the shadows, but in the case of Russia’s invasion of Ukraine, skirmishes have come out in the open, although the scale has not been as anticipated.</p>



<p class="wp-block-paragraph">Cyber warfare has been happening between them since the collapse of the Soviet Union in 1991. Russian cyber weapon Uroburos had been around since 2005. In 2013, Op Armageddon, a Russian campaign of systematic cyber espionage on the information systems of government agencies, law enforcement, and defence agencies, began to help Russia on the battlefield. The victims of Russian cyber attacks were government agencies of Ukraine, the EU, the United States, defense agencies, international and regional defence and political organizations, think tanks, the media and dissidents.</p>



<p class="wp-block-paragraph">Ukraine power grid was first successfully hacked in Dec 2015 and then again in Dec 2016. The State Treasury of Ukraine was paralysed in Dec 2016. The largest known mass supply-chain attack took place in June 2017 using Petya virus.</p>



<p class="wp-block-paragraph">Other Russian attacks have included wiper virus NotPetya inserted into tax accounting software used by Ukrainian firms, which encrypts computers permanently. Malware dubbed Hermetic Wiper prevented computers from rebooting.</p>



<p class="wp-block-paragraph">As part of cyber access denial and skirmishes restrictions were imposed on Facebook by the Russian government, prompting Facebook to ban ads from Russian state media. Google’s YouTube platform banned state media adverts. Elon Musk, a US tech titan, provided satellite internet access to Ukraine via his Starlink satellites.</p>



<p class="wp-block-paragraph">Ukraine launched cyber attacks under Operation Groundbait in May 2016. The Surkov Leaks in Oct 2016 made public 2,337 e-mails and hundreds of attachments, with plans for seizing Crimea from Ukraine and fomenting separatist unrest in Donbas. The IT Army of Ukraine was established in Feb 2022 during the 2022 Russian invasion of Ukraine.</p>



<p class="wp-block-paragraph">Anonymous, the hacker collective has declared cyberwar on Russia. The group has claimed credit for hacking the Russian Ministry of Defence database, and is believed to have hacked multiple state TV channels to show pro-Ukraine content.</p>



<p class="wp-block-paragraph">The group has claimed credit for several distributed denial of service attacks. Its targets in the past have included the CIA, the Church of Scientology and Islamic State</p>



<p class="wp-block-paragraph">Anonymous&#8217; Russian targets included:</p>



<ul class="wp-block-list"><li>Roskomnadzor, the Russian government agency in charge of controlling access to social media sites.</li><li>Russian news channels Russia 24, Channel One, and Moscow 24.</li><li>Kremlin’s official website, the Ministry of Defence database, over 300 Russian media, as well as banking websites.</li><li>Hacktivists wanted to keep Russians connected to the rest of the world and alternative media by publishing their data in the hope of exposing the censorship that the Russian government was putting on its citizens.</li></ul>



<h3 class="wp-block-heading">Top Cyberattacks of 2021</h3>



<p class="wp-block-paragraph">There are millions of cyber attacks every year. Some prominent ones in 2021 were as follows:</p>



<p class="wp-block-paragraph"><strong>Colonial Pipeline.</strong> In May of 2021, Russian hacking group DarkSide attacked Colonial Pipeline, a significant fuel provider, impacting petroleum, diesel, and jet fuel supplies across the East Coast of America.</p>



<p class="wp-block-paragraph"><strong>Brenntag.</strong> In May 2021, DarkSide also targeted a German chemical distribution company, Brenntag, stealing 150 GB of encrypted data, demanding ransom. $4.4 million was paid.</p>



<p class="wp-block-paragraph"><strong>Acer.</strong> REvil hacker group attacked Taiwanese computer giant, Acer, demanding $50 million as ransom.</p>



<p class="wp-block-paragraph"><strong>CNA Financial.</strong> In March 2021, CNA Financial, a US insurance company was attacked which compromised data of 75,000 people. CNA Financial eventually paid $40 million to regain access.</p>



<p class="wp-block-paragraph"><strong>Facebook, Instagram, and LinkedIn.</strong> Social profiles of 214 million social media users (408 gigabytes of compromised data) from these platforms were exposed by a Chinese social media management company called Socialarks.</p>



<p class="wp-block-paragraph"><strong>Bombardier.</strong> Canadian plane manufacturer, Bombardier, suffered in February 2021 compromise of the confidential data of suppliers and customers in Feb 2021.</p>



<p class="wp-block-paragraph"><strong>Sierra Wireless.</strong> IoT device manufacturer Sierra Wireless was hit by a ransomware attack and had to halt production at its manufacturing in Mar 2021.</p>



<h3 class="wp-block-heading">Recent Initiatives</h3>



<p class="wp-block-paragraph">The creation of the Defence Cyber Agency in 2019, Cyber Security Coord at the National Security Council (NSC), preparedness for offensive ops by the National Technical Research Organisation (NTRO), defensive measures by National Critical Info Infrastructure Protection Centre (NCIIPC) and the release of India&#8217;s National Cyber Security Policy (NCSP) are steps in the right direction. As roles and responsibilities of the armed forces, other government agencies as well as the private sector are articulated, the nation&#8217;s vulnerability to cyber attacks will decrease.</p>



<p class="wp-block-paragraph">The vulnerabilities facing India’s Critical Infrastructure (CI) need to be addressed with greater urgency. Cyber attacks against India’s CI and Strategic Infrastructure (ST), such as nuclear power plants, are not new.</p>



<p class="wp-block-paragraph">Defensive measures like having a cyber security framework, Cyber Security Awareness, Incident Response Tools, Vulnerability Assessment and Penetration Testing, Multi-Factor Authentication and so on are necessary but offensive defence is the key. Along with space, Indian must prepare for “cross-domain” warfare to include cyberspace.</p>



<p class="wp-block-paragraph">Webinar Sessions</p>



<p class="wp-block-paragraph">The webinar has been organised into the following sessions:</p>



<p class="wp-block-paragraph">(a)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Session 1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; Inaugural</p>



<p class="wp-block-paragraph">(b) &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Session 2 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; Cyber Security Technologies</p>



<p class="wp-block-paragraph">(c)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Session 3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; Countermeasures Framework for Military Networks</p>



<p class="wp-block-paragraph">(d)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Session 4 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; Critical Infrastructure Vulnerabilities &amp; Protection</p>



<p class="wp-block-paragraph">(e)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Session 5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; Cyber Warfare Doctrine and Superiority</p>



<p class="wp-block-paragraph"><strong>ALSO READ:</strong> <a href="https://infosecconferences.com" target="_blank" rel="noreferrer noopener">Infosec Conferences</a></p>
<p>The post <a href="https://imrmedia.in/event-preview-cyber-defence-india-2022/">Event Preview: Cyber Defence India 2022</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/event-preview-cyber-defence-india-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Pakistan collaborating with China in cyber attacks against India</title>
		<link>https://imrmedia.in/pakistan-collaborating-with-china-in-cyber-attacks-against-india/</link>
					<comments>https://imrmedia.in/pakistan-collaborating-with-china-in-cyber-attacks-against-india/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 11 Feb 2022 06:18:00 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[Advanced Persistent Threats]]></category>
		<category><![CDATA[anti-India propaganda]]></category>
		<category><![CDATA[APT attack]]></category>
		<category><![CDATA[China-Pak collaboration]]></category>
		<category><![CDATA[China-Pakistan collusion]]></category>
		<category><![CDATA[China's proxy]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber defence]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[defense news]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[Pakistan-China]]></category>
		<category><![CDATA[proxy war]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=12282</guid>

					<description><![CDATA[<p>Russian cybersecurity firm Kaspersky’s latest ‘Cyberthreats to Financial Organizations in 2022’ report mentions that India is one of the top five targets for cyber-attacks in the Asia Pacific region, particularly the APT (Advanced Persistent Threats) cyber-attacks which exploit gaps in cyber defences, and remain undetected for a long time. According to Kaspersky, the APT attacks [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/pakistan-collaborating-with-china-in-cyber-attacks-against-india/">Pakistan collaborating with China in cyber attacks against India</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Russian cybersecurity firm Kaspersky’s latest ‘Cyberthreats to Financial Organizations in 2022’ report mentions that India is one of the top five targets for cyber-attacks in the Asia Pacific region, particularly the APT (Advanced Persistent Threats) cyber-attacks which exploit gaps in cyber defences, and remain undetected for a long time. According to Kaspersky, the APT attacks are expected to increase in the coming years. Kaspersky’s findings reflect the growing expansion of India’s cyber threat canvas, primarily dominated by penetrating attacks from Pakistan and China.</p>



<p class="wp-block-paragraph">There is good reason to suspect China-Pak collaboration in cyberspace. In recent years, Beijing and Islamabad have deepened their co-operation in the information technology domain. Digital and cyber co-operation are crucial elements of the ‘Long-Term Plan for China-Pakistan Economic Corridor (2017-2030)’. The plan emphasises ICT-enabled development and promotion of e-commerce in Pakistan.</p>



<p class="wp-block-paragraph">But beyond this benign collaboration, China-Pakistan collusion has become a reality where Pakistan has emerged as a proxy for China’s malicious designs. This is particularly true with respect to anti-India propaganda on social media platforms.</p>



<p class="wp-block-paragraph">During the ongoing border stand-off between India and China along the Line of Actual Control, Pakistan-based Twitter handles posing as Chinese nationals have peddled anti-India propaganda. These Twitter handles have regularly peddled misleading reports related to the violent clash at Galwan Valley in June 2020, as well as about India’s military preparedness. China and Pakistan are also potentially exploring establishing an international news media outlet that will significantly advance their propaganda efforts. Besides, in 2018, both had reportedly joined hands to honey trap Indian Army officers into revealing information regarding troop deployments along the borders with China and Pakistan.</p>



<p class="wp-block-paragraph">The Chinese side has taken the lead by providing the technology and content, while Pakistan acts as the implementer and disseminator. This collaboration is symbiotic: China needs Pakistan because mainstream social media platforms such as Twitter and Facebook are banned in China, and command over the English and Hindi languages is very limited in most parts of China’s populace. Moreover, by not directly getting involved and making Pakistan the front end of the anti-India activity, China is able to skirt attribution. For Pakistan, collaborating with China strengthens its strategic partnership and lends the technical edge, which Islamabad’s cyber activities wouldn’t have been able to achieve otherwise.</p>



<p class="wp-block-paragraph">This cyber collusion is also likely to extend to malicious cyber activities such as APT attacks, with the intention to collect valuable geopolitical, business, and military data. Indian cybersecurity researchers have suspected Chinese assistance to Pakistani cyber campaigns like APT36’s ‘Operation Sidecopy.’ The APT36 is a known threat actor that has used fake COVID-19 health advisory to launch phishing attacks against Indian defence networks to steal confidential information. The threat vector had been active since 2016, indicative of its long duration. Most recently, Pakistan-based hackers conducted a major cyber-attack targeting India’s power generation and transmission sector using the platform supplied by China Mobile Limited, which operates under the brand Zong 4G in Pakistan.</p>



<p class="wp-block-paragraph">Evidence of Pakistan’s emergence as China’s proxy in cyberspace lies not only in China’s active role in enhancing Pakistan’s ICT infrastructure as part of the China-Pakistan Economic Corridor (CPEC), but more so in the modus operandi of cyber actors in both countries at the tactical level involving fake propaganda-based influence operations, and espionage using malware as well as honey traps.</p>



<p class="wp-block-paragraph">With China-Pakistan cyber collusion becoming a reality, India must prepare for the spectre of a ‘two-front war’ in cyberspace. While their cyber-espionage operations cause loss of sensitive information, their disinformation campaigns — based on anonymity and deniability — pose the real danger of accentuating the existing political polarisation, and social divisions within India.</p>



<p class="wp-block-paragraph">Moreover, these disinformation campaigns can yield a significant advantage to Pakistan and China by sowing the seeds of doubt among the citizens about their national institutions’ credibility. Therefore, India needs to effectively counter the menace of China-Pakistan cyber collaboration as it has not just national security implications, but indeed implications for India’s democracy as a whole.</p>



<p class="wp-block-paragraph">In recent years, India has taken steps to plug its cyber vulnerabilities through several legal and institutional measures. Yet, Chinese and Pakistani hackers continue to capitalise on the lack of adequate cybersecurity awareness and poor cyber hygiene practices, such as not checking the veracity of ‘fake news’, clicking on unsolicited web links, among average Indian Internet users, to ensure that their propaganda efforts get the necessary traction, and their malwares breach sensitive computer networks.</p>



<p class="wp-block-paragraph">Therefore, even as India strengthens its cyber defences by plugging its vulnerabilities, it must implement two steps. At the micro-level, India should increase the citizens’ resilience to emerging cyber threats, and expand cyber hygiene initiatives. At the macro-level, India must amplify its offensive cyber posture to clearly signal its intentions and deter its adversaries.</p>



<p class="wp-block-paragraph">These steps are necessary for India to prepare for China-Pakistan’s ‘hybrid warfare’.</p>
<p>The post <a href="https://imrmedia.in/pakistan-collaborating-with-china-in-cyber-attacks-against-india/">Pakistan collaborating with China in cyber attacks against India</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/pakistan-collaborating-with-china-in-cyber-attacks-against-india/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
