Campaign, Jan 2021 to Apr 2022.View on attack.mitre.org
Indian Critical Infrastructure Intrusions is a sequence of intrusions from 2021 through early 2022 linked to People’s Republic of China (PRC) threat actors, particularly RedEcho and Threat Activity Group 38 (TAG38). The intrusions appear focused on IT system breach in Indian electric utility entities and logistics firms, as well as potentially managed service providers operating within India. Although focused on OT-operating entities, there is no evidence this campaign was able to progress beyond IT breach and information gathering to OT environment access.
| Technique | Procedure example |
|---|---|
| T1071.001 Web Protocols |
During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports. |
| T1568 Dynamic Resolution |
During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1571 Non-Standard Port |
During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication. |
| T1573.002 Asymmetric Cryptography |
During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication. |
| T1583.001 Domains |
During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| T1584 Compromise Infrastructure |
Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity. |
| T1588.004 Digital Certificates |
Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft. |
| T1599 Network Boundary Bridging |
Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.