Part of the blame for the instability and full disarray in Afghanistan has been placed on Pakistani malware. Some experts claimed that if...
seen from United States
seen from Poland

seen from United States
seen from United States
seen from Russia
seen from United States
seen from United States
seen from United States
seen from Singapore
seen from United States
seen from China
seen from South Korea
seen from Germany
seen from United Kingdom

seen from Türkiye

seen from Türkiye
seen from South Korea
seen from Türkiye
seen from United States

seen from United States
Part of the blame for the instability and full disarray in Afghanistan has been placed on Pakistani malware. Some experts claimed that if...
Protection against cybercrime is an urgent necessity for developing countries. The government is keeping check on Indian offensive cyber...
The vulnerabilities in the Indian ecosystem have only grown over time. Amid growing cyberattacks, India’s top cybersecurity agency CERT-In...
INDIA IS EMBROILED IN A WEB OF ALLEGATIONS OVER THE USE OF ISRAELI SPYWARE PEGASUS
The Fifth-generation war is a war of perspectives and India aims to improve its position by becoming the most targeting nation amid the changing war composition. In order to do so, the country is developing both the offensive and defensive cyber capabilities taking help from both the domestic and foreign firms.
A recently disclosed data that suggested India’s use of Israeli spyware – Pegasus has invoked huge criticism for the country. The investigation suggested that the Indian government is targeting its own citizens, although the country has named it baseless accusations.
Over time, powerful non-state groups that use asymmetric warfare tactics to attack the adversaries have emerged in India. The private actors serve India’s geopolitical and geo-strategic interests, giving rise to Indian cyberwarfare and hybrid warfare. Its cooperation with the foreign nations is helping it to attack the adversary’s cyberspace in the most impactful way.
The growing use of mercenaries, non-state actors, etc. is overall challenging the fundamental values of the world order. The states are using new war tactics – information warfare, hybrid warfare, disinformation campaigns etc. to deliver attacks.
India has been cooperating with Israel in the cyber field since 2018. Cybersecurity has become a growing and natural area of close cooperation between India and Israel. A cyber agreement was signed between both the countries to deal with the growing cyber threats amid rapid digitisation.
The move was considered as an important step in confronting the global cyber threats. A recent revelation stated that India has been an important customer of NSO Group of Israel. It used the NSO Group’s spyware to target phone numbers of politicians, dozens of journalists, and businessmen in the country.
The NSO client country is also accused of posing a huge threat to the neighbouring adversary – Pakistan, since the Israeli software has the ability to infect a device without the target’s engagement or knowledge.
Pakistan believes that the phone number previously used by the country’s Prime Minister Imran Khan was a part of surveillance hacking attempt via the Pegasus software and hence an investigation is in the process. Since the data is organised in clusters, it does not reveal the attack details of the NSO clients, thereby holding a total of 10 governments responsible for the attacks.
As per the Indian government, the Pegasus Project report was published by disrupters to help the obstructers in the Parliament. Meanwhile, the political parties are now demanding the Indian government to come out with the truth and their dealings with NSO Group.
It’s not the first time where India has cooperated with the foreign country in the cyber field. In the wake of growing cyber attacks from China, North Korea and Pakistan, the largest democracy in the world has also signed cyber agreements with the US and Russia. Simultaneously, it is building cyber offensive capabilities with the help of private actors.
Indian private firms like Phronesis, Aglaya, Dark Basin, and other APT groups like Viceroy Tiger, SideWinder, and APT C-35 have launched malware attacks against the adversaries. These firms are making sure that India continues to advance in the cyber offensive front while the cooperation and the national cyber strategy to make it better are intact.
About Pegasus:
Owned by the NSO Group, Pegasus spyware enables the remote surveillance of smartphones. It allows secret unlocking of the target’s mobile phone, including the contents, overall transforming it into a listening device. The Israeli firm claims that it sells spyware only to the vetted governments around the world to combat terrorism and other crimes.
Pakistani APT Group Imitates Indian Cyber Operation Methods to Deliver Malware Attack
Creating secure cyberspace in India has become more strenuous in the wake of persistent cyberattacks on the country. The malware attacks by adversaries have not only targeted the critical infrastructure in India but have advanced to the government and the military sector too.
As a developing country, India possesses cyber offensive and defensive capabilities that could ward off attacks from adversaries. India’s cyber offensive front has been stepped up by the private firms that have launched cyber operations against the neighbouring adversaries covertly. Lately, some of the adversaries are even copying the methods used by the Indian cyber threat groups to launch malware attacks.
One of the Pakistani threat groups called SideCopy was spotted imitating the Indian threat group SideWinder’s infection chains to deliver its own set of malware. SideCopy hackers appear to be highly motivated by the attack methods used by Indian APT groups like SideWinder that have been plaguing governments and enterprises in South Asia and East Asia since 2012. Other Indian groups that have come into the limelight for the same purpose include Dark Basin, Phronesis, Aglaya, etc.
SideWinder Advanced Persistent Threat group has been progressing in offensive cyber operations for a long time now. The firm was spotted using the Binder exploit to attack mobile devices. It proactively targeted victims that included multiple government and military units – in China, India, Nepal, and Pakistan using social-engineering techniques.
At present, SideCopy is actively copying techniques reserved for Sidewinder. Seqrite, Quick Heal’s enterprise security brand stated that the Pakistani cyber-espionage group has been active since 2019. The threat intelligence team first uncovered the spear-phishing campaigns in September 2020.
The team analysed that most of the old attacks were related to ‘Operation SideCopy’ by common IOCs. Cisco Talos, one of the networking giant’s cybersecurity divisions stated that the group has continued to launch cyber operations against the Indian government and military. They used spear-phishing email attacks each of which came with malicious file attachments—ranging from LNK files to self-extracting RAR EXEs and MSI-based installers—that installed remote access trojans (RATs) on infected systems.
SideCopy operators deployed RAT plugins that ranged from file enumerators to credential-stealers and keyloggers. The APT group’s activities posed a close resemblance to the campaigns initiated by another Pakistani threat group called APT36 (aka Mythic Leopard and Transparent Tribe), which has recently shifted its focus to Afghanistan. The Talos report has stated that the sophistication of attacks has comparatively increased and more visible in 2020 and 2021. It also reported a spike in activity by Chinese security firm – Rising.
The cyber-espionage efforts between India and Pakistan have been in continuation for more than five years now. Both the countries are keeping tabs on each other using cyberwarfare capabilities, while aggressively pursuing advanced infection techniques to ‘infect the victims’.
India is Formulating National Cyber Strategy While Building Cyberwarfare Capacity
Over time, state-led or non-state hybrid warfare has multiplied the cybercrime attack options with higher frequency throughout the globe. In India, geopolitical tensions have sped up the process of developing offensive and defensive cyber capabilities. In addition, the government is also looking to unveil a national cyber strategy that would holistically cover the entire Indian cyberspace ecosystem.
In a recent conference organised by the Public Affairs Forum of India, the Indian National Cybersecurity Coordinator Lt. Gen. Rajesh Pant explained the critical aspects of cyberspace. He stated that cyberspace is witnessing technological bipolarity in the geopolitical world and that it is split between the US and China, each advancing with the help of its allies.
Secondly, he stressed India’s need to formulate its approach towards the cyber issue by establishing a national cyber strategy. India is quickly emerging as a new cyber power and a formidable opponent all because of the cyber offensive capabilities it is building with the help of private actors. Following the threats in cyberspace that have become more pertinent, Indian APT groups like Dark Basin, CyberRoot, Phronesis, etc., have been reinforcing India’s cyber front and targeting adversaries.
Recently, China evolved a new internet protocol and even released the Global Initiative on Data Security (GIDS) for the world. It has been aiming to take the control of the data security narrative away from the US when the latter came up with the concept of a “clean network with trusted equipment.” It has built several hacking organisations, many of which have repeatedly targeted Indian cyberspace.
The Chinese threat group – RedEcho’s attack on the Indian power grid in 2020, the Chinese state-backed hackers attacked the IT infrastructure and supply chain software of Bharat Biotech and the Serum Institute of India (SII), the world’s largest vaccine maker and, Chinese state-sponsored threat actor APT41’s attack on SITA, a multinational IT company providing services to the air transport industry, and other airlines, including the Air India, were some of the major recent attack incidents by China.
China’s aggressive cyber-espionage activities have been condemned by several western countries. The US congressman Frank Pallone even urged the Biden administration to support the strategic partner – India. The aim has been to work together on cybersecurity to counter fifth-generation warfare.
The cyber cooperation in the wake of geopolitical tensions has also motivated the threat actors in India to expand the activity ground. They are now getting varying levels of state support to develop the national offensive cyber capabilities. Further, the national cyber strategy to be launched this year would ensure safe, secure, resilient, vibrant, and trusted cyberspace. This will subsequently maintain the global balance of power.
What is India’s Hybrid Warfare Strategy against the Adversary Nations?
Following the cyberspace battle, the countries around the world are building cyber offensive and defensive capabilities, while employing overt tactics to overcome their adversaries. India being the most targeted country in cyberspace, by tier two countries, is now exerting influence with the help of hybrid warfare strategy.
The consequences of hybrid warfare are considered the most lethal in the present world, for the modus operandi is irregular, uncertain, and varies from the old military war tactics. However, to counter the growing attacks from the neighbouring nations, India is adopting all the present-day global warfare tactics to knock out the regional rivals.
In 2020, FireEye described the cyberattacks on India as “the broadest campaigns by a Chinese cyber espionage actor in recent years. Several Chinese threat groups used phishing emails or Trojan malware and targeted vulnerable systems and devices that remained exposed to the internet.
So India stepped up its cyber offensive game with the help of private actors. From launching malware attacks to campaigning fake news and foreign political intervention, Indian non-state actors took advantage and attacked the adversaries in a comprehensive manner.
It wouldn’t be wrong to say that the non-state actors in India have defended India against cyberattacks from time to time. They have strengthened India’s cyber warfare potential, while their violent measures fitted the contemporary definitions of hybrid warfare.
In the wake of information warfare, Pakistan became the most targeted victim of Indian non-state actors. India’s Srivastava Group played an important role in discrediting Pakistan internationally. The Indian firm launched nearly 750+ fake media sites that promoted pro-government content worldwide in retaliation to Pakistan’s anti-India sentiments.
In the 15-year long global operation, the group targeted the European Union and the United Nations. Later, it even resurrected the dead media, dead individuals, think tanks, and NGOs, launching wide-scale disinformation campaigns to defame Pakistan on a global scale.
The Indian threat groups have also launched malware attacks on the regional rivals. Earlier this year, Cyberroot Risk Advisory, an Indian firm that provides cyber forensics investigation, penetration testing, physical access control, and security testing, etc. was seen to be involved in controversial incidents of hack-and-leak cases. A deep dive into the company’s business shed light upon its businesses in the Middle East and Asia.
A Delhi-based company – BellTrox that was in limelight last year for the ‘years-long hacking campaign’ that targeted more than 10,000 accounts across the globe, was involved with the CERT-In Empanelled Security Audit Company. Meanwhile, several other APT groups like SideWinder, Viceroy Tiger, etc. continued to pose prolific threats to Indian adversaries via phishing and malware attacks.
It is the lethality of the measures followed by the non-state actors that have influenced the definitions of hybrid warfare. These threat actors have proved that India has capabilities and is much more successful in terms of waging war against adversaries.
Pakistan and China Team Up to Wage Propaganda Warfare on India
The cyberattacks from neighbouring adversaries have blurred the national boundaries. It has become necessary for India to confront these acts of propaganda warfare comprehensively. Amid the growing concept of cyberwarfare in South Asia, India is consequently seeking to balance its offensive and defensive cyber capabilities.
Over time Indian APT groups like C-35, SideWinder, Viceroy Tiger, and firms like Srivastava Group and Phronesis have played major roles in deploying India’s offensive cyber capabilities against the growing propaganda warfare. Meanwhile, firms like Lucideus, Kratikal Tech Pvt Ltd, Data Resolve Technologies, Techdefence Labs, and others are bolstering India’s cyber defences.
A recently released report from Graphika stated that Pakistan had been using misinformation campaigns to manipulate social media networks and denigrate India. Efforts were being made to praise Pakistan and its armed forces, through false media channels while promoting issues like human rights violations in India.
The leaked documents intercepted by the Indian intelligence agencies also stated that Pakistan wants to launch information warfare against India by collaborating with China. The concept paper titled ‘Building capacity to contest inimical narratives through counter on alternative narratives’ stated China’s role in providing finances and guidance to Pakistan.
China is competing with the West in technology and economy. But winning in the social media-dominated world is not easy. China has been targeted for the persecution of the Muslim Uighur population in the Xinjiang region. Moreover, its continuous strike on Indian cyberspace through misinformation campaigns and cyber offensives has evoked huge criticism for the country.
China has also assisted Pakistan in cyber warfare and cybersecurity assistance. An Information Security Lab is being set up under the National Electronics Complex of Pakistan in the cyber warfare domain.
By funding Pakistan, China intends to repair its long-tarnished image. On the other hand, Pakistan too has helped China, by playing pro-China narratives. During the Galwan Valley clash, Pakistan launched misinformation against India, outspreading that only a few Chinese soldiers were injured during the clash.
Such collaborations in cyber technology have brought a new paradigm of digital risk to India. The country has emerged as a major business and IT outsourcing hub, catering to international markets across industries. But, today it faces the threat of malicious attackers and privacy breaches.
Data from CERT-In suggested that India witnessed a 300% increase in the number of cyberattacks in 2020 over 2019. The wide-scale cyber operations against India shed light on the APT groups and campaigns that originated to strengthen the country’s cyber front and end the propaganda warfare. The Indian private actors launched offensive cyber operations – malware attacks and disinformation campaigns, to counter Pakistan and China’s cyber propaganda. They have aided the country in standing up to the global trend of cyberwarfare.