Moneycontrol
HomeNewsBusinessChina-based threat actors target UIDAI, AIIMS, ICMR: Govt advisory
Trending Topics

China-based threat actors target UIDAI, AIIMS, ICMR: Govt advisory

The advisory issued in mid-May showed that the government detected the cyberattack campaign in February 2023. The advisory warned that the malware infection was likely to increase in government organisations, "as there is no antivirus capable of detecting these malicious files".

June 09, 2023 / 12:51 IST
Story continues below Advertisement

PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups

The government has detected a "new wave of cyber attack campaign" where China-based threat actors have been targeting government bodies, such as the Unique Identification Authority of India (UIDAI) and the All India Institute of Medical Sciences (AIIMS), according to a cybersecurity advisory accessed by Moneycontrol. This comes at a time when there have been relentless cyberattacks on government organisations, with AIIMS recently clarifying that it was able to thwart a separate malware attack.

An investigation by government bodies showed that critical organisations, including the Indian Council of Medical Research (ICMR), were being targeted with PlugX/Korplug malware, which is associated with Chinese threat actors.

Story continues below Advertisement

PlugX/Korplug is a remote access tool with plugins that are used by multiple threat groups, according to MITRE ATT&CK, a knowledge base of adversary tactics and techniques in cyberspace. Various cybersecurity firms, such as Anomali and CrowdStrike, have conducted research linking the usage of PlugX/Korplug malware to China-based threat groups, such as Mustang Panda.

The advisory issued in mid-May showed that the government detected the cyberattack campaign in February 2023. The advisory warned that the malware infection was likely to increase in government organisations, "as there is no antivirus capable of detecting these malicious files".