Some India Security Agencies Hit by Cyber Spying Malware: Symantec

Advertisement
By Gadgets 360 Staff With Inputs From Reuters | Updated: 28 August 2017 16:01 IST
Highlights
  • Symantec said the online espionage effort dated back to October 2016
  • The campaign appeared to be the work of several groups
  • Symantec did not identify the likely sponsor of the attack

Symantec, a digital security company, says it has identified a sustained cyber spying campaign, likely state-sponsored, against Indian and Pakistani entities involved in regional security issues.

In a threat intelligence report that was sent to clients in July, Symantec said the online espionage effort dated back to October 2016, according to news agency Reuters.

The campaign appeared to be the work of several groups, but tactics and techniques used suggest that the groups were operating with "similar goals or under the same sponsor", probably a nation state, according to the threat report, which was reviewed by Reuters. It did not name a state.

Advertisement

The detailed report on the cyber spying comes at a time of heightened tensions in the region.

Advertisement

The Indian military had raised operational readiness along its border with China following a face-off near the border in Sikkim, while Indo-Pakistan tensions are also simmering over Islamabad's support to terror groups that operate in Kashmir.

A spokesman for Symantec said the company does not comment publicly on the malware analysis, investigations and incident response services it provides clients.

Advertisement

Symantec did not identify the likely sponsor of the attack. But it said that governments and militaries with operations in South Asia and interests in regional security issues would likely be at risk from the malware. The malware utilises the so-called "Ehdoor" backdoor to access files on computers.

"There was a similar campaign that targeted Qatar using programs called Spynote and Revokery," said a security expert, who requested anonymity. "They were backdoors just like Ehdoor, which is a targeted effort for South Asia."

Advertisement

To install the malware, Symantec found, the attackers used decoy documents related to security issues in South Asia. The documents included reports from Reuters, Zee News, and the Hindu, and were related to military issues and Kashmir.

The malware allows spies to upload and download files, carry out processes, log keystrokes, identify the target's location, steal personal data, and take screenshots, Symantec said, adding that the malware was also being used to target Android devices.

In response to frequent cyber-security incidents, India in February established a center to help companies and individuals detect and remove malware. The center is operated by the Indian Computer Emergency Response Team (CERT-In).

Gulshan Rai, the director general of CERT-In, declined to comment specifically on the attack cited in the Symantec report, but added: "We took prompt action when we discovered a backdoor last October after a group in Singapore alerted us." He did not elaborate.

Symantec's report said an investigation into the backdoor showed that it was constantly being modified to provide "additional capabilities" for spying operations.

A senior official with Pakistan's Federal Investigation Agency said it had not received any reports of malware incidents from government information technology departments. He asked not to be named due to the sensitivity of the matter.

A spokesman for FireEye, another cyber-security company, said that based on an initial review of the malware, it had concluded that an internet protocol address in Pakistan had submitted the malware to a testing service. The spokesman requested anonymity, citing company policy.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Symantec, Cyber Attack, Malware, India, Ehdoor
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Saiyaara is All Set to Stream on This OTT Platform in September
  3. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  4. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  5. Realme 15T 5G India Launch Today: All You Need to Know
  6. Total Lunar Eclipse 2025: When and Where to Watch the Blood Moon Safely
  7. Vivo Launches Y500 in China With a Massive 8,200mAh Battery
  8. OpenAI Could Soon Build This Massive AI Infrastructure in India
  9. Google Debunks Gmail Security Warning Reports, Calls It Entirely False
  10. Poco C85 With 6,000mAh Battery, Helio G81-Ultra SoC Debuts at This Price
  1. Vivo X300 Series to Use Samsung’s New 200-Megapixel ISOCELL HPB Sensor for Stills, Portrait Photography
  2. Apple Reportedly Pushes Supply Chain Partners to Ramp Up Automation Upgrades
  3. Total Lunar Eclipse 2025: When and Where to Watch the Blood Moon Safely
  4. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  5. Oppo Find X9 Design Spotted in Leaked Render; Performance Revealed via Geekbench
  6. Google Debunks Gmail Security Warning Reports, Calls It Entirely False
  7. Realme 15T Launched in India With 7,000mAh Battery, 50-Megapixel Selfie Camera: Price, Specifications
  8. Bitcoin Conspiracy Thriller Killing Satoshi Starring Casey Affleck, Pete Davidson Expected to Release in 2026
  9. 007 First Light Is Getting a Gameplay Deep Dive at Sony's State of Play This Week
  10. OnePlus 15 Will Reportedly Arrive With Company's New, Propreitary Camera Engine
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.