<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber operations | IMR</title>
	<atom:link href="https://imrmedia.in/tag/cyber-operations/feed/" rel="self" type="application/rss+xml" />
	<link>https://imrmedia.in/tag/cyber-operations/</link>
	<description>Indian Military Review, Defense News, Indian Defence Review</description>
	<lastBuildDate>Fri, 31 Mar 2023 05:51:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://imrmedia.in/wp-content/uploads/2020/04/cropped-IMR-Logo-512x512-px-32x32.jpg</url>
	<title>cyber operations | IMR</title>
	<link>https://imrmedia.in/tag/cyber-operations/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Peng Cheng Laboratory</title>
		<link>https://imrmedia.in/peng-cheng-laboratory/</link>
					<comments>https://imrmedia.in/peng-cheng-laboratory/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Sun, 15 Jan 2023 09:01:00 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[Neighbourhood]]></category>
		<category><![CDATA[China Cyber capabilities]]></category>
		<category><![CDATA[China's Cyber Ranges]]></category>
		<category><![CDATA[cyber offensive]]></category>
		<category><![CDATA[cyber operations]]></category>
		<category><![CDATA[Cyber Ranges]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyber-espionage]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[non-state actors]]></category>
		<category><![CDATA[Peng Cheng Laboratory]]></category>
		<category><![CDATA[PLA]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15928</guid>

					<description><![CDATA[<p>One Among 19 Cyber Ranges in China With government funding, massive computational capacity, and ties to the military, Peng Cheng Lab is likely to be actively used by state hacking teams. Notably, this cyber range, which facilitates military-civil fusion, has supercomputers, research facilities for AI, ICS, smart cars, etc. It is known to have hosted [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/peng-cheng-laboratory/">Peng Cheng Laboratory</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">One Among 19 Cyber Ranges in China</h2>



<p class="wp-block-paragraph">With government funding, massive computational capacity, and ties to the military, Peng Cheng Lab is likely to be actively used by state hacking teams. Notably, this cyber range, which facilitates military-civil fusion, has supercomputers, research facilities for AI, ICS, smart cars, etc. It is known to have hosted cyber competitions.</p>



<p class="wp-block-paragraph">The lab is led by the Guangdonag Provincial Laboratory of Cyberspace Science and Technology and built with funding from the Guangdong provincial and Shenzhen municipal governments. It aims to provide computational power to groups conducting research on a large number of topics.</p>



<p class="wp-block-paragraph">Based on the lab&#8217;s known partnerships (see below), these groups include academics, industry, and military researchers. Peng Cheng Lab enumerated areas of research extends to robotics, virtual reality, smart lasers, and “electromagnetic cognition.”</p>



<p class="wp-block-paragraph">Peng Cheng Lab has built a powerful supercomputer, Cloudbrain-II Based on available data, Cloudbrain-II is estimated to be half as fast as the world&#8217;s fastest supercomputer, Fugaku in Japan. Its most famous contribution to China&#8217;s public research so far has been the computational power it provided to train China&#8217;s PanGu large language model. Peng Cheng Lab aims to provide similar computation resources to work on cyber ranges and AI and cyber research.</p>



<p class="wp-block-paragraph">Peng Cheng Lab also hosts cyber ranges for industrial control systems, smart cars, cybersecurity development, and AI. The facility&#8217;s work on industrial control systems appears aimed at securing IoT devices used to implement “smart manufacturing”—a policy goal formalized in a recent five-year plan. Smart cars, part of the electric vehicle revolution and a topic of concern in China&#8217;s Three-Year Action Plan for the High-Quality Development of the Cybersecurity Industry (2021-2023), receive their own cyber range. The Internet of Vehicles Lab is being built in concert with central government regulators under the China Automotive Technology and Research Center in Tianjin.</p>



<p class="wp-block-paragraph">Peng Cheng Lab issued contracts to build its AI cyber range within months of opening in 2019. The contracts were quickly followed with public events promoting research on AI in China. The Shenzhen-based lab hosted China&#8217;s National AI Competition in late 2020, which counted leaders from the Chinese Academy of Engineering, leading Chinese universities, and private firms among its participants.</p>



<p class="wp-block-paragraph">Projects focused on cybersecurity advanced just as quickly. Peng Cheng Lab hosted an inaugural conference on cyber range research in mid-2019 and has done so at least once since then. After China&#8217;s National Cybersecurity Center for Education and Innovation opened in 2020, Peng Cheng Lab began partnering with the facility. In 2021, Peng Cheng Lab joined the National Cybersecurity Center, Sichuan University, and a cybersecurity park in Qingdao in jointly hosting a cybersecurity competition. Qi An Xin Technology Group, a Chinese cybersecurity company active at the National Cybersecurity Center and one of China&#8217;s 20 “invisible champions” of national security technology, may have facilitated Peng Cheng Lab&#8217;s engagement—the company won a contract to construct Peng Cheng Lab&#8217;s AI cyber range. The lab&#8217;s rapid integration into existing cybersecurity and AI research initiatives across the country by Qi An Xin indicate it is taken seriously by other leading researchers in China. As of 2022. such cooperation appears to be organic and not centrally dictated.</p>



<p class="wp-block-paragraph">The lab&#8217;s list of partners is growing rapidly. Since opening its doors in 2019, Peng Cheng Lab has formed research partnerships with other Chinese institutions. The lab partners with 21 universities, 13 research organizations, and 25 businesses or SOEs. Among the organizations participating in the initiative, prominent institutions include several of China&#8217;s premier universities, such as Peking University, Tsinghua University, and the Chinese Academy of Sciences. One school tied to state-sponsored hacking campaigns and co-located on a PLA base, Shanghai Jiao Tong University, also partners with Peng Cheng Lab. Shanghai Jiao Tong University is also subject to a 2017 agreement with the PLA Strategic Support Force to develop “new combat forces.”</p>



<p class="wp-block-paragraph">Likewise, China&#8217;s National University of Defense Technology and the Key Laboratory of Science and Technology for National Defense are listed among its partnerships with research organizations. The collection of collaborators reads as a who&#8217;s who of Chinese high-tech research talent. Peng Cheng Lab names entities like BGI, China Aerospace Science and Industry Corporation, China Electronics Corporation, China Electronics Technology Group, iFlyTek, and HiSense among its corporate and defense-SOE partners. The US Department of Commerce has listed many of these businesses on its Entity List.</p>



<p class="wp-block-paragraph">Of the cyber ranges discussed in this report, Peng Cheng Lab stands out for its association with Li Jianhua, a professor at Shanghai Jiao Tong University. Li currently runs a PLA-affiliated lab which researches the applications of AI to cybersecurity research for both offensive and defensive purposes. His work is also featured in Robot Hacking Games, China&#8217;s version of DARPA&#8217;s Cyber Grand Challenge.</p>



<p class="wp-block-paragraph">Li is one of China&#8217;s leading experts on cyber policy. In 2018, he published an article extolling the importance of cyber ranges and offered a detailed path for successful development. Li argued that the ability to rapidly recreate networks is critically important, a capability which can facilitate attack planning. He specifically suggested the use of AI to aid both defenders in detecting intrusions and in “decision making” during range operations.</p>



<p class="wp-block-paragraph">Given Li&#8217;s prominence, his involvement in Peng Cheng Lab suggests it is among the more sophisticated cyber ranges developed by China. His involvement, his school&#8217;s history of working with China&#8217;s security services, the technical capabilities of the lab, and the lab&#8217;s partnership with military institutions indicate it may be used by the PLA to practice offensive operations. Li&#8217;s institution, Shanghai Jiao Tong University, is listed among the lab&#8217;s strategic partners, alongside defense-SOEs and the PLA&#8217;s National University of Defense Technology. Further, given Li&#8217;s focus on AI and ties to the security services, Peng Cheng Lab is well-situated to enable AI-aided attack planning. One possible scenario would allow offensive operators to further hone their attacks by applying machine learning to attack simulations made possible by the range.</p>



<p class="wp-block-paragraph">Based on &#8220;Downrange: A Survey of China&#8217;s Cyber Ranges&#8221;, A report by Center for Security and Emerging Technology, 2022</p>
<p>The post <a href="https://imrmedia.in/peng-cheng-laboratory/">Peng Cheng Laboratory</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/peng-cheng-laboratory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>China&#8217;s Cyber Ranges for Attack and Defence</title>
		<link>https://imrmedia.in/chinas-cyber-ranges-for-attack-and-defence/</link>
					<comments>https://imrmedia.in/chinas-cyber-ranges-for-attack-and-defence/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Sun, 15 Jan 2023 08:56:00 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[Neighbourhood]]></category>
		<category><![CDATA[China Cyber capabilities]]></category>
		<category><![CDATA[China's Cyber Ranges]]></category>
		<category><![CDATA[cyber offensive]]></category>
		<category><![CDATA[cyber operations]]></category>
		<category><![CDATA[Cyber Ranges]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyber-espionage]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[non-state actors]]></category>
		<category><![CDATA[Peng Cheng Laboratory]]></category>
		<category><![CDATA[PLA]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15924</guid>

					<description><![CDATA[<p>State, PLA and Private Companies’ Collaboration China is rapidly building cyber ranges that allow cybersecurity teams to test new tools, practice attack and defence, and evaluate the cybersecurity of a particular product or service. Nineteen of China&#8217;s 34 provinces are building, or have built, such facilities. Their purposes span from academic to national defence. In [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/chinas-cyber-ranges-for-attack-and-defence/">China&#8217;s Cyber Ranges for Attack and Defence</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>State, PLA and Private Companies’ Collaboration</strong></h2>



<p class="wp-block-paragraph">China is rapidly building cyber ranges that allow cybersecurity teams to test new tools, practice attack and defence, and evaluate the cybersecurity of a particular product or service. Nineteen of China&#8217;s 34 provinces are building, or have built, such facilities.</p>



<p class="wp-block-paragraph">Their purposes span from academic to national defence. In short, the presence of these facilities suggests a concerted effort on the part of the government, in partnership with industry and academia, to advance technological research and upskill its cybersecurity workforce—more evidence that China has entered near-peer status in the cyber domain.</p>



<p class="wp-block-paragraph">A report titled “Downrange: A Survey of China&#8217;s Cyber Ranges&#8221;, by the Center for Security and Emerging Technology, published in September 2022, examines some of China&#8217;s 19 facilities that have demonstrable ties to the military or security services.</p>



<p class="wp-block-paragraph">China&#8217;s investment in cyber ranges is in line with what is known about other efforts to bolster the country&#8217;s hacking and cybersecurity capabilities. As these facilities mature, network defenders who find themselves in the crosshairs of China&#8217;s hacking teams may be subject to attacks that have been rehearsed, tested, and sometimes practiced on replicas of their own networks.</p>



<h3 class="wp-block-heading">Important Findings</h3>



<p class="wp-block-paragraph">This report finds:</p>



<p class="wp-block-paragraph">1. China&#8217;s cyber ranges facilitate joint exercises between the People&#8217;s Liberation Army (PLA) and civilians. One competition hosted each year in Chengdu aims to replicate the North Atlantic Treaty Organization&#8217;s (NATO) Locked Shields exercise. Teams include representatives from the military, private cybersecurity firms, and critical infrastructure operators. Separately, a defence state-owned enterprise (SOE) makes a “comprehensive space scenario range” available to civilians at an annual cybersecurity competition. Each of these examples demonstrates China&#8217;s implementation of military-civil fusion in the cyber domain.</p>



<p class="wp-block-paragraph">2.&nbsp;Some cyber ranges allow hackers to practice attacking and defending critical infrastructure systems. Some ranges provide users with training on industrial control systems within the cyber range; one of which purportedly engages in “national offensive and defensive exercises.” The Office of the U.S. Director of National Intelligence&#8217;s 2022 unclassified annual threat assessment found that China was “almost certainly [&#8230;] capable of launching cyberattacks that would disrupt critical infrastructure services.” These ranges could allow rehearsals and testing of these types of attacks in the future.</p>



<p class="wp-block-paragraph">3. Peng Cheng Laboratory in southern China is using a supercomputer to research artificial intelligence&#8217;s (AI) application to cybersecurity. The lab&#8217;s partners include the National University of Defense Technology, China&#8217;s Key Laboratory of Science and Technology for National Defense, and Shanghai Jiao Tong University, a university with ties to military hacking teams. The lab has quickly earned the respect of longtime experts in China&#8217;s cybersecurity community.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="600" height="486" src="https://imrmedia.in/wp-content/uploads/2023/03/National-Cyber-Security-School.jpg" alt="National Cyber Security School" class="wp-image-15926" srcset="https://imrmedia.in/wp-content/uploads/2023/03/National-Cyber-Security-School.jpg 600w, https://imrmedia.in/wp-content/uploads/2023/03/National-Cyber-Security-School-300x243.jpg 300w, https://imrmedia.in/wp-content/uploads/2023/03/National-Cyber-Security-School-519x420.jpg 519w" sizes="(max-width: 600px) 100vw, 600px" /><figcaption>National Cyber Security School</figcaption></figure></div>



<h3 class="wp-block-heading">Ranges Enhance Chinese Defence</h3>



<p class="wp-block-paragraph">China&#8217;s cybersecurity posture will be enhanced by the use of cyber ranges in several ways. First, China&#8217;s critical infrastructure, massive data troves, and government agencies will be better defended. Cybersecurity teams with years of experience and hours of practice on a range will be better able to defend against a variety of threats. Second, China&#8217;s attacks are likely to increase in efficacy and capability. While there are no indications to date that China has launched a physically destructive or disruptive cyberattack against another country&#8217;s critical infrastructure, the ranges covered in this report suggest such a lack of action may be based in policy rather than from a lack of capabilities. Besides making attacks on industrial control systems more feasible, other types of attacks will improve as well. For example, hacking teams have more opportunities to try new tactics, techniques, and procedures.</p>



<h3 class="wp-block-heading">Components of Cyber Ranges</h3>



<p class="wp-block-paragraph">Cyber ranges can help these agencies provide the experiential learning that hackers need. A set of virtual machines—software that creates a computer within a computer— comprise most cyber ranges. Because virtual machines are cheap software to license, a cyber range can quickly grow in size but with little additional cost. The operator can design the range to his or her needs, specifying how the machines are connected, what operating system they use, and even the range&#8217;s defences. The best cyber ranges aim to simulate real computer networks. Few achieve this high standard, and for most users &#8220;close&#8221; is good enough. The best government-funded cyber ranges can simulate millions of connections.</p>



<p class="wp-block-paragraph">But cyber ranges do not only let users learn new tools, they also let them practice. Offensive teams that hope to damage or impair physical systems with precision often need to rehearse. Attacking an electrical substation or gas pipeline requires deep knowledge about the target. A cyber range built to emulate that target can help attackers make sure that they are on the right path. Industrial networks can be recreated from stolen data; AI may even help attackers understand how to attack these systems.</p>



<h3 class="wp-block-heading">Background and Recent Policies</h3>



<p class="wp-block-paragraph">The Chinese Academy of Sciences (CAS) established China&#8217;s first national cyber range in 2010. That was China&#8217;s first publicly-acknowledged, government-led effort to establish such a facility. Some of China&#8217;s best universities, military hacking teams, and private cybersecurity firms likely already had access to cyber ranges.</p>



<p class="wp-block-paragraph">Cyber ranges within China featured prominently in 2021 in two important ways. First, the Ministry of Industry and Information Technology began soliciting public opinions on the drafted Three-Year Action Plan for the High-Quality Development of the Cybersecurity Industry (2021-2023) in July 2021. MIIT policymakers called on the government and industry to build “AI security cyber ranges,” promote research on cyber ranges, use cyber ranges for training, and invest in cyber ranges that can be used to train defenders of China&#8217;s futuristic smart cities. MIIT frequently allocates money for research on cyber ranges, including allotments to research partnerships between universities and the PLA Strategic Support Force—the service branch responsible for computer network operations and space systems.</p>



<p class="wp-block-paragraph">China issued its second policy addressing cyber ranges a few months later in October 2021. The National Industrial Information Security Development Research Center, a research institute of the MIIT, published a document whose contents were only summarized publicly. In the policy document, titled “Industrial Cyber Range Platform Technology Capability Evaluation Criteria”, policymakers lay out the standards that China&#8217;s Industrial Control System cyber ranges should aspire to meet. Available summaries reference standards from companies such as Dragos, KPMG, EY, and Deloitte. What little information is publicly available stresses the close connection between industrial security and China&#8217;s future as an automated manufacturing powerhouse.</p>



<h3 class="wp-block-heading">Private Sector Participation</h3>



<p class="wp-block-paragraph">China, like many countries, has a robust market for cyber range providers. Private sector companies sell services to universities so cybersecurity students can practice their skills. Some companies specialize in supporting critical infrastructure operators, helping electrical grid operators learn how to defend their networks. And still some companies focus on training other private sector employees. Similarly, it is well known that China&#8217;s premier military university for hackers—the PLA Information Engineering University—has a cyber range.</p>



<h3 class="wp-block-heading">Potential Cyber Range Uses in China</h3>



<p class="wp-block-paragraph">There are a number of potential uses of cyber ranges. The following have been observed in China:</p>



<p class="wp-block-paragraph">●&nbsp;Training on new tools and techniques in a controlled environment.</p>



<p class="wp-block-paragraph">●&nbsp;Practicing attacking and defending industrial control systems.</p>



<p class="wp-block-paragraph">●&nbsp;Evaluating product cybersecurity—smart cars, Internet of Things (IoT) devices, etc.</p>



<p class="wp-block-paragraph">●&nbsp;Evaluating the efficacy of cybersecurity/antivirus products. Such evaluations can determine whether the products will detect new attack methodologies or malware. These evaluations can also help attackers evade a target&#8217;s defences. China&#8217;s military has been observed purchasing such systems.</p>



<p class="wp-block-paragraph">●&nbsp;Recreating networks to allow defenders to practice defending those systems and attackers to practice attacking targeted systems.</p>



<p class="wp-block-paragraph">● Planning attacks using attack graphs, which recreate a network and determine which pathways to a target are least likely to pique the interest of defenders. Some researchers are using an AI technique, reinforcement learning, to determine and optimize these attack paths.</p>



<p class="wp-block-paragraph">● Replicating smart-city networks for defenders to practice protecting internet- connected infrastructure and surveillance systems.</p>



<h3 class="wp-block-heading">Conclusion</h3>



<p class="wp-block-paragraph">The development of China&#8217;s cyber ranges highlights how its military-civil fusion strategy is applied to the cyber domain, leveraging academic institutions, companies and government labs/entities to work toward a central goal. These ranges not only provide the opportunity for civilian organizations and the military to practice their skills together, but they also consistently engage in national security related research in areas such as applying machine learning frameworks to software vulnerability discovery, applying AI to cyberattack and defence, and developing attack and defence methodologies for industrial control systems.</p>



<p class="wp-block-paragraph">The growth of China&#8217;s cyber ranges is not accidental. Central policymakers signalled their interest in cyber ranges for education, training, AI development, and testing in China&#8217;s most recent development plan for the cybersecurity sector. Consequently, municipal and provincial governments funded the development of cyber ranges with sometimes significant subsidies in alignment with Beijing&#8217;s political mandate. Other cyber ranges included in the appendix receive similar funding across China. The decentralized approach to investment supports innovation by provincial governments and increases opportunities for cooperation and collaboration between the military and civilians.</p>



<p class="wp-block-paragraph">Cyber ranges are key to training the next generation of talent to defend, and potentially attack, critical infrastructure. China—through the development of its ranges—is providing a venue for testing and exercising the tools and techniques to attack and defend critical infrastructure while developing the technical talent to execute these operations. Although no cybersecurity firms or governments have yet attributed a disruptive or destructive attack on industrial control systems to China, this report on its cyber ranges demonstrates that the PLA has the capabilities to do active research in this area and could be postured to conduct such attacks in the future. New research on Chinese procurement records and research publications shows Chinese interest in procuring the capabilities for such destructive attacks, following the 2015 attack on Ukraine&#8217;s electrical grid. China&#8217;s interest in having that capability is likely driving those requests.</p>



<p class="wp-block-paragraph">As new cyber range capabilities develop and mature, the lessons learned from their use will provide more policy options to Beijing. Competition among states for influence and power in China&#8217;s near-abroad will continue to shape Beijing&#8217;s policy in the region. Besides positive incentives that induce cooperation, such as trade deals, disincentives—like potentially learning that Beijing has implanted destructive malware on your country&#8217;s electrical grids—bolster China&#8217;s ability to compel other countries.</p>



<p class="wp-block-paragraph">Although the time and place of future cyber operations is hard to predict, the scope and scale of China&#8217;s operational capabilities is growing. Investment precedes capabilities, and China has invested.</p>



<p class="wp-block-paragraph">Based on &#8220;Downrange: A Survey of China&#8217;s Cyber Ranges&#8221;, A report by Center for Security and Emerging Technology, 2022</p>
<p>The post <a href="https://imrmedia.in/chinas-cyber-ranges-for-attack-and-defence/">China&#8217;s Cyber Ranges for Attack and Defence</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/chinas-cyber-ranges-for-attack-and-defence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber Year in Review</title>
		<link>https://imrmedia.in/cyber-year-in-review/</link>
					<comments>https://imrmedia.in/cyber-year-in-review/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Sun, 15 Jan 2023 08:28:00 +0000</pubDate>
				<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[Cyber capabilities]]></category>
		<category><![CDATA[cyber offensive]]></category>
		<category><![CDATA[cyber operations]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyber-espionage]]></category>
		<category><![CDATA[DDoS attack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Khalifah Cyber Crew]]></category>
		<category><![CDATA[non-state actors]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15918</guid>

					<description><![CDATA[<p>What to Expect in 2023? India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claimed. The government itself [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/cyber-year-in-review/">Cyber Year in Review</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">What to Expect in 2023?</h2>



<p class="wp-block-paragraph">India, US, Indonesia, and China accounted for 45% of total cyberattacks on government agencies worldwide in the second half of 2022, according to a report by cybersecurity firm CloudSek, released on 30 December. The number of attacks on government agencies were up 95% year-on-year, the report claimed.</p>



<p class="wp-block-paragraph">The government itself has acknowledged that 18 million cyberattacks and 200,000 online threats daily in the first quarter of 2022.</p>



<p class="wp-block-paragraph">India was the most targeted country in 2022 as attacks on government agencies more than doubled. CloudSek attributed this to an increase in activities of Malaysia-based hacktivist group Dragon Force, which ran campaigns such as #OpIndia and #OpsPatuk against India in retaliation to the controversial comments by an Indian politician on Prophet Mohammed.</p>



<p class="wp-block-paragraph">Another hacker group Khalifah Cyber Crew intensified attacks on India in protest against alleged “Muslim discrimination&#8221; by the government, the report said.</p>



<p class="wp-block-paragraph">Attacks on government agencies in China declined to 4.5% of all attacks from 13.10% last year. On the other hand, in India, US, and Indonesia, the share of all attacks grew from 6.3% to 13.7%, 7.4% to 9.6%, and 4.6% to 9.3%, respectively.</p>



<h3 class="wp-block-heading">CERT-In Data</h3>



<p class="wp-block-paragraph">Government data, collated by the Ministry of Electronics and Information Technology&#8217;s Indian Computer Emergency Response Team (CERT-In), is available only till 2021, but that too shows an increase in cyberattacks in India.</p>



<p class="wp-block-paragraph">In 2019, CERT-In handled close to 3,94,499 incidents in total, in which it suggested remedial measures for organisations and shared notes on “cyber threats and vulnerabilities”. In the same year, CERT-In issued 204 security alerts and 38 advisories.</p>



<p class="wp-block-paragraph">The number of incidents handled by CERT-In surged in 2020 to 11,58,208, a near-tripling over the previous year. This surge continued in 2021, which saw 14,02,809 incidents, a 21 per cent increase.</p>



<p class="wp-block-paragraph">The matters CERT-In looks into include website intrusion and malware propagation, malicious code, phishing, distributed denial-of-service (DDoS) attacks, website defacements, unauthorised network scanning or probing activities, ransomware attacks, data breaches and vulnerable services.</p>



<h3 class="wp-block-heading">Trends</h3>



<p class="wp-block-paragraph">The Indian Computer Emergency Response Team said: “Threat actors were leveraging tools that are already available in the cyber environment rather than making custom tools and malwares. By this way, they were being able to bypass many security controls.”</p>



<p class="wp-block-paragraph">Threat actors are also able to execute scripts that reboot victim&#8217;s machine into &#8216;safe mode&#8217;, and thus bypass security solutions.</p>



<p class="wp-block-paragraph">In terms of mitigation, the agency recommended victims to immediately disconnect and isolate infected systems from the network. IT also recommended to turn off any wireless internet connectivity and isolate all system backups.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="600" height="348" src="https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India.jpg" alt="Attacks by Vertical in India" class="wp-image-15921" srcset="https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India.jpg 600w, https://imrmedia.in/wp-content/uploads/2023/01/Attacks-by-Vertical-in-India-300x174.jpg 300w" sizes="(max-width: 600px) 100vw, 600px" /><figcaption>Attacks by Vertical in India</figcaption></figure></div>



<h3 class="wp-block-heading">Spike in Ransomware Attacks in India</h3>



<p class="wp-block-paragraph">In a first of its kind report, the Indian Computer Emergency Response Team (CERT-In) said that it had observed a 51 percent increase in ransomware incidents in the country in the first half of the business year (H1) in 2022.</p>



<p class="wp-block-paragraph">The information technology sector was the most affected when it came to these attacks, CERT-In said, followed by manufacturing and finance.</p>



<p class="wp-block-paragraph">CERT-In attributed the rise in attacks in India to Djvu, a &#8216;high-risk&#8217; virus that majorly targets citizens. The agency also named Phobos, a ransomware which “strikes smaller companies and individuals that have less capacity to pay relative to larger businesses”, to have played a role in the increase.</p>



<p class="wp-block-paragraph">It also attributed the increase to Hive, a year-old ransomware which has grown into one of the most prevalent ransomware payloads in the ransomware-as-a-service (RaaS) ecosystem, according to Microsoft.</p>



<h3 class="wp-block-heading">&#8220;Ransomware as a Service&#8221;</h3>



<p class="wp-block-paragraph">A ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. Ransomware as a service (RaaS) is a subscription-based model that enables affiliates to use already-developed ransomware tools to execute ransomware attacks, said Upguard, a cybersecurity company.</p>



<p class="wp-block-paragraph">In the report CERT-In said, “Ransomware-As-A-Service (RAAS) ecosystem is evolving with sophisticated double and triple extortion tactics and a wide range of ransomware campaigns through affiliates.”</p>



<p class="wp-block-paragraph">“This is leading to higher probability of monetization and further rise in attack campaigns. Post covid accelerated digitalisation and hybrid work culture are also aiding this threat emergence,” it added.</p>



<h3 class="wp-block-heading">Modus Operandi</h3>



<p class="wp-block-paragraph">The agency noted that ransomware gangs were focusing on penetrating known unpatched vulnerabilities of public facing applications for gaining entry into the network.</p>



<p class="wp-block-paragraph">“Compromised credentials of remote access services (VPN/ RDP) are being used by threat actors to gain entry into the network,” it said.</p>



<p class="wp-block-paragraph">Apart from that, CERT-In said phishing campaigns are also another major source of ransomware infections.</p>



<p class="wp-block-paragraph">Zerofox describes a phishing campaign as a scam created by cybercriminals to steal financial resources or sensitive data from victims using manipulative emails or other fraudulent digital assets.</p>



<h3 class="wp-block-heading">State of Affairs</h3>



<p class="wp-block-paragraph">In recent times the three most notorious members of the ransomware family- Ryuk, Purga, and Stop made major headlines in the nation.</p>



<p class="wp-block-paragraph">The Stop ransomware caused about 10.10% of the ransomware attacks followed by Ryuk making about 5.84% attacks along with Purga for deploying 0.80% of ransomware attacks</p>



<p class="wp-block-paragraph">Ryuk seemed to have been the most active threat landscape in the Indian public as well as private sectors. On the other hand, brute-force attacks on RDP and SMBs seemed to have steadily increased in the last five years.</p>



<p class="wp-block-paragraph">According to Forbes, there was one ransomware attack every 10 seconds in 2020.</p>



<p class="wp-block-paragraph">Reportedly, organizations have faced double extortion in 2020 across the globe. Moreover, the cost of ransomware damage is predicted to hit around $20 billion by 2021.</p>



<p class="wp-block-paragraph">Although, this figure may vary later depending upon the cost of attacks and their devastating consequences. To know how brutal ransomware attacks can get, here are the top devastating ransomware attacks that took place in India.</p>



<h3 class="wp-block-heading">Hacktivism</h3>



<p class="wp-block-paragraph">In 2022, hacktivism accounted for 9% of the cyberattacks on the government sector. Hacktivism is a form of cyberattack where the hacker&#8217;s motivation is not financial gains but to promote a political agenda or protest against certain policies. Last year, attacks on China also increased due to its aggressive stance towards Taiwan and the Uyghur community.</p>



<p class="wp-block-paragraph">In addition to hacktivism, government agencies in India are also increasingly being targeted by phishing campaigns, according to the report.</p>



<h3 class="wp-block-heading">Ransomware Attacks</h3>



<p class="wp-block-paragraph">CloudSek also found that ransomware groups were very active and accounted for 6% of the attacks on governments. LockBIT, which provides ransomware-as-a-service (RaaS) was the most prominent ransomware operator. Its targets in 2022 included government agencies in the US, Canada, and Italy. In November, a Russian national was arrested in Canada for alleged involvement in LockBIT ransomware campaigns in the US.</p>



<p class="wp-block-paragraph">In November 2022, India&#8217;s top government-run hospital All India Institute of Medical Science (AIIMS) was also hit by a cyberattack causing disruption of online services that lasted over two weeks. India&#8217;s nodal cybersecurity agency Computer Emergency Response Team (CERT-In) found in its investigation that five AIIMS&#8217; servers were compromised during the attack and nearly 1.3 terabytes of data was encrypted by hackers.</p>



<h3 class="wp-block-heading">What to Expect in 2023</h3>



<p class="wp-block-paragraph">Experts believe that state-sponsored hackers will go after cloud services in 2023 due to growing digital transformation. “Nation states will begin to target cloud service provider (CSP) managed services as companies migrate more of their attack surface to these managed services,&#8221; according to Bob Huber, chief security officer at Tenable, a cybersecurity firm.</p>



<p class="wp-block-paragraph">India&#8217;s had its worst year of cyberattacks, but 2023 will see govt &amp; firms ramp up defences</p>



<p class="wp-block-paragraph">India was a top target for cyberattacks in 2022, shows study by web security firm Indusface. As govt tries to address policy vacuum, companies likely to spend more on cybersecurity.</p>



<p class="wp-block-paragraph">According to a study released Tuesday by Indusface, a Tata Capital-funded software-as-a-service (SaaS) security firm, India has become one of the most attacked and breached countries in the world. Among the 829 million cyber-attacks detected and blocked globally by the firm in the fourth quarter of 2022, close to 59 per cent were directed towards India.</p>



<p class="wp-block-paragraph">In this backdrop, what will the government and companies do differently in the coming year?</p>



<p class="wp-block-paragraph">As the government readies its legislation on cybersecurity, numerous industry-wide surveys and sector experts say that 2023 will see companies spending significant amounts to secure their digital systems from attacks.</p>



<p class="wp-block-paragraph">According to Sajan Paul, managing director &amp; country manager, India &amp; SAARC, Juniper Networks, a “zero trust” policy will be an “essential security strategy” for India, going forward. &#8216;Zero trust&#8217; model assumes breach and verifies each request as though it originates from an open network.</p>



<h3 class="wp-block-heading">Data protection Bill and CERT-In rules</h3>



<p class="wp-block-paragraph">India&#8217;s IT ministry has come up with the Digital Personal Data Protection Bill, 2022, defining some roles of data fiduciaries and introducing appellate committees that will deal with redressals and grievances. Many have termed it a “step in the right direction” to ensure data security.</p>



<p class="wp-block-paragraph">The draft law, alongside CERT-In rules, has been part of core policy discussions in India. The rules now require companies to report cybersecurity incidents within six hours. While this seems stringent, it might not be practical, some experts believe. This was perhaps the most significant development in the cybersecurity domain in 2022.</p>



<h3 class="wp-block-heading">Commentary</h3>



<p class="wp-block-paragraph">Cyberattacks on government agencies are not new. Many of these attacks state sponsored and are aimed at stealing sensitive information or cripple critical infrastructure of other countries. Indian entities are often targeted by hacker groups with links to China. Similarly, many of the attacks on US agencies often originate from Russia or North Korea.</p>



<p class="wp-block-paragraph">According to IBM&#8217;s &#8216;Cost of Data Breach Report 2022&#8217;, the average cost of data breaches in the government sector has increased from $1.93 million in 2021 to $2.07 million this year.</p>



<p class="wp-block-paragraph">Threat actors have modernised their attack methodologies, evolved sophisticated tactics and adopted a wide range of attack campaigns.</p>



<p class="wp-block-paragraph">==</p>



<h2 class="wp-block-heading">Top Six Attacks in 2020-21</h2>



<h3 class="wp-block-heading">Telangana and AP Power</h3>



<p class="wp-block-paragraph">A malicious software attacked the power utility systems of&nbsp; Telangana and Andhra Pradesh in 2020 where all the servers went down until the glitch was rectified. Since the computer systems of Telangana and Andhra Pradesh power utilities were interlinked, the virus attack quickly spread, taking down all the systems.</p>



<h3 class="wp-block-heading">UHBVN Ransomware Attack</h3>



<p class="wp-block-paragraph">Uttar Haryana Bijli Vitran Nigam was hit by a ransomware attack where the hackers gained access to the computer systems of the power company and stole the billing data of customers. The attackers demanded Rs.1 crore or $10 million in return for giving back the data.</p>



<h3 class="wp-block-heading">WannaCry</h3>



<p class="wp-block-paragraph">India was the third worst-hit nation by WannaCry ransomware, affecting more than 2 lakh computer systems. During the first wave of attacks, this ransomware attack had hit banks in India including few enterprises in Tamil Nadu and Gujarat. The ransomware majorly affected the US healthcare system and a well-known French car manufacturing firm.</p>



<h3 class="wp-block-heading">Mirai Botnet Malware Attack</h3>



<p class="wp-block-paragraph">This botnet malware took over the internet, targeting home routers and IoT devices. This malware affected 2.5 million IoT devices including a large number of computer systems in India. This self-propagating malware was capable of using exploitable unpatched vulnerabilities to access networks and systems.</p>



<h3 class="wp-block-heading">Petya</h3>



<p class="wp-block-paragraph">India was one of the top 10 countries to be hit by Petya ransomware. This ransomware attack halted work at one of the terminals of India&#8217;s largest seaport causing computer lockdown and serious consequences for the country&#8217;s exports.</p>



<h3 class="wp-block-heading">BSNL Malware Attack</h3>



<p class="wp-block-paragraph">The state-owned telecom operator BSNL was hit by a major malware attack, impacting nearly 2000 broadband modems! 60,000 modems became dysfunctional after the malware attack hit the Telecom Circle.</p>
<p>The post <a href="https://imrmedia.in/cyber-year-in-review/">Cyber Year in Review</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/cyber-year-in-review/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>EDITORIAL—China’s Cyber Arsenal</title>
		<link>https://imrmedia.in/editorial-chinas-cyber-arsenal/</link>
					<comments>https://imrmedia.in/editorial-chinas-cyber-arsenal/#respond</comments>
		
		<dc:creator><![CDATA[Maj Gen (Dr) GD Bakshi, SM, VSM]]></dc:creator>
		<pubDate>Sun, 15 Jan 2023 08:11:00 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Neighbourhood]]></category>
		<category><![CDATA[China Cyber capabilities]]></category>
		<category><![CDATA[cyber offensive]]></category>
		<category><![CDATA[cyber operations]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyber-espionage]]></category>
		<category><![CDATA[Editorial]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[non-state actors]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15911</guid>

					<description><![CDATA[<p>China flatly denies accusations of cyber warfare, and has, instead, accused the United States of engaging in cyber warfare against it. However, China has consistently engaged in offensive cyber operations, and as the scope of the country&#8217;s economic and political ambitions expanded, so has its cyber footprint. The number of China-sponsored and aligned hacking teams [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/editorial-chinas-cyber-arsenal/">EDITORIAL—China’s Cyber Arsenal</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">China flatly denies accusations of cyber warfare, and has, instead, accused the United States of engaging in cyber warfare against it. However, China has consistently engaged in offensive cyber operations, and as the scope of the country&#8217;s economic and political ambitions expanded, so has its cyber footprint. The number of China-sponsored and aligned hacking teams are growing, as they develop and deploy offensive cyber capabilities to serve the state&#8217;s interests — from economic to national security.</p>



<p class="wp-block-paragraph">Chinese non-state actors are very involved in Chinese cyber operations. A wide variety of non-state entities, such as contractors and technology conglomerates (Alibaba, Huawei, etc.), have worked in tandem with the CCP on a variety of research, development, and execution of cyber operations.</p>



<p class="wp-block-paragraph">Over the years, PLA unit officers have been indicted in the US on charges of theft of confidential business information from U.S. commercial firms and planting malware on their computers.</p>



<p class="wp-block-paragraph">Chinese state-sponsored cyber actors aggressively target U.S. and Allied political, economic, military, educational, and critical infrastructure (CI) personnel and organizations to steal sensitive data, emerging and key technology, intellectual property, and personally identifiable information (PII), including political targets and now have the ability to influence elections. In March 2021, United States intelligence community released analysis in finding that China had considered interfering with the election but decided against it on concerns it would fail or backfire.</p>



<p class="wp-block-paragraph">While cyber espionage for national security concerns is a common action conducted by most countries, cyber espionage for economic benefit is an accusation continually made against the Chinese government and military.</p>



<p class="wp-block-paragraph">China is focussed towards developing the domestic technology industry and its capabilities, to counter the “eight King Kongs” (Apple, Cisco, Google, IBM, Intel, Microsoft, Oracle, and Qualcomm).</p>



<p class="wp-block-paragraph">The scale of China&#8217;s cyber operations dwarfs those of other countries in the region—the complexity and sheer range of targeting, and the number of domestic technology companies whose increasingly global reach may be utilized for intelligence gain and influence.</p>



<p class="wp-block-paragraph">Beijing has nurtured a tech industry and environment that actively support the party-state&#8217;s aims to bolster government surveillance and cyber capabilities. From large firms to startups, many companies work with the state to conduct vulnerability research, develop threat detection capabilities, and produce security and intelligence products.</p>



<p class="wp-block-paragraph">In India, most major attacks on Indian government networks, such as the National Security Council, have originated from China. Chinese hackers are experts in operating botnets. Multiple instances of Chinese cyber attacks against India&#8217;s cyberspace have been reported including ransomware attack on the servers of All India Institute of Medical Sciences in&#8230;</p>



<p class="wp-block-paragraph">India needs a a culture of cyber security investment and strategy. At the very least, we need to ensure security personnel monitor key internal security capabilities and can identify anomalous behaviour. Any known Chinese state-sponsored indicators of compromise and tactics, techniques, and procedures must be identified for immediate response.</p>
<p>The post <a href="https://imrmedia.in/editorial-chinas-cyber-arsenal/">EDITORIAL—China’s Cyber Arsenal</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/editorial-chinas-cyber-arsenal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
