What this piece does
In October 2020, Mumbai went dark. In November 2022, AIIMS Delhi's hospital servers stopped talking to each other. In February 2024, a trove of leaked contracts from a Shanghai hacking contractor showed India's Prime Minister's Office listed as a target. All three of those facts are true, and all three have been cited, at one time or another, as proof of a Chinese state cyberattack on India. Only one of them actually is.
That gap matters more than it looks. India sits inside one of the most persistently targeted cyber-espionage relationships in the world -- the evidence for that is real, current, and gets stronger every month. But the public narrative around it has accumulated some claims that don't survive contact with their own source material, and repeating them uncritically does the opposite of what good threat intelligence is supposed to do: it teaches defenders to distrust attribution generally, which is exactly the ambiguity state-sponsored operators rely on.
This piece does two things a shorter summary can't. First, it catches the story up to what's actually running today -- two live campaigns as of this writing, one of them still beaconing inside Indian government machines. Second, and less commonly done, it goes back through the years of accumulated claims about Chinese responsibility -- in English, Chinese, and Hindi-language sources -- and grades each one against what the primary investigators and officials actually said, not what got summarized six times removed. Some of it holds up extremely well. Some of it doesn't, and we say so plainly.
The doctrine, updated
The strategic framework behind all of this is still the one Beijing wrote down in December 2003: the "Three Warfares" (Sān zhǒng zhàn fǎ), embedded in the PLA's Political Work Regulations -- public-opinion/media warfare, psychological warfare, and legal warfare, all designed to coerce without crossing into open conflict. Cyber operations are the delivery mechanism for all three: pre-positioning in critical infrastructure functions as psychological signaling even when nothing is ever switched off; mass data theft feeds "public opinion" operations by giving Beijing material to profile, pressure, or discredit; and the whole apparatus operates through commercial contractors specifically so the state can deny direct involvement -- lawfare's evidentiary cousin.
What's changed since that doctrine was last widely written up in India-focused coverage is the institution running it. On April 19, 2024, the PLA dissolved its Strategic Support Force -- the body that had housed China's cyber and space warfare units since 2015 -- and split its functions into three new arms reporting directly to the Central Military Commission: the Aerospace Force, the Cyberspace Force, and the Information Support Force. It's the PLA's biggest reorganization in a decade, and it means older reporting that anchors Chinese cyber operations against India to a single named unit (Fuzhou's Unit 61716/"Base 311," stood up in 2005 for Taiwan-focused operations) is describing an organizational chart that no longer exists in that form. The operational playbook against India hasn't visibly changed; the command structure running it has.
The contractor economy, and the strongest evidence in this dossier
Much of what's publicly known about who is actually doing this work comes not from malware reverse-engineering but from a single event: the February 2024 leak of internal files from I-Soon (安洵信息, Anxun), a Shanghai contractor founded in 2010 by a "red hacker" using the alias "shutdown." Someone -- never publicly identified -- posted hundreds of pages of contracts, marketing decks, product manuals, employee chat logs, and target lists to GitHub. Independent technical reviews (SentinelOne's foundational analysis, Malwarebytes, HarfangLab, and others) assess the leak as authentic.
This is worth dwelling on, because it's the strongest category of evidence in this entire investigation -- stronger than any single piece of malware forensics discussed later in this post. Researching the leak directly in Chinese turns up material that doesn't show up in most English-language summaries: a leaked target list titled "安洵渗透海外政府部门" ("Anxun Penetrating Overseas Government Departments") names Indian government bodies explicitly -- the President's Office, the Ministry of Home Affairs, the Ministry of External Affairs, the Ministry of Defence, the Ministry of Finance, plus border/immigration data tables and basic landline-subscriber records. Leaked internal chat records -- reported by Radio Free Asia's Mandarin service and corroborated by Epoch Times' Chinese edition and VOA Chinese -- show I-Soon employees explicitly discussing the Indian government as "Beijing's geopolitical rival" and listing it as a primary "penetration" target, alongside Nepal, Hong Kong, Taiwan, South Korea, and Malaysia.
This is closer to a documentary confession than a technical attribution: it isn't inferred from shared malware code or overlapping infrastructure, it's the contractor's own internal paperwork, sold to named clients. The leak also documents pricing -- I-Soon charged Chinese state security agencies the equivalent of $10,000 to $75,000 per successfully compromised email inbox -- and a specific data haul from India's Bureau of Immigration: 95.2 GB of entry/exit records through 2020, useful for tracking the movements of Indian military, diplomatic, and intelligence personnel across borders.
One honest caveat belongs here, because it cuts the other way from the rest of this paragraph: a contractor's own marketing and target materials are exactly the kind of document that gets embellished to impress a paying government client. Visibility into what I-Soon listed as a target or claimed to have accessed is not automatic proof every listed intrusion succeeded to the degree described. The chat logs also show a company under real strain -- employees complaining about low pay, threatening arbitration, and considering other jobs -- a high-burnout environment that is itself a data point (it's the kind of workforce that produces operational mistakes and insider-threat risk, not an unstoppable machine).
The U.S. response to the leak has since put names to the operation. In March 2025, the Justice Department indicted 12 individuals: eight I-Soon employees including CEO Wu Haibo and COO Chen Cheng, two Ministry of Public Security officers, and two additional hackers, Zhou Shuai and Yin Kecheng. The State Department separately sanctioned Zhou Shuai and his company, Shanghai Heiying Information Technology, and the Rewards for Justice program is offering $10 million for information leading to identification of the group's operators. This is a rare case where "Chinese state-linked hackers" resolves into an actual list of named, indicted people rather than remaining an abstraction.
KnownSec, a second Chinese contractor whose data leaked in a separate 2024 incident, corroborates the same commoditized ecosystem: a vertically integrated toolkit for webmail XSS exploitation, session hijacking, cookie replay, and full inbox exfiltration, sold the same way I-Soon's services were.
AI on the offense: what's confirmed, and what isn't
Dragonbridge (also tracked as Spamouflage; Microsoft calls the network Storm-1376) is the most prolific PRC-aligned influence operation, running coordinated inauthentic accounts across 175+ websites and 58 languages since at least 2019. Microsoft's Threat Intelligence team has explicitly named India, alongside South Korea and the United States, as a target of the network's generative-AI-assisted disinformation, and documented the network using AI-synthesized audio deepfakes and AI-rendered "news anchors" during Taiwan's January 2024 election -- the first documented nation-state attempt to influence a foreign election with AI-generated content.
What we could not independently confirm, despite specifically searching for it, is a named, documented Dragonbridge operation against a specific Indian election. Reporting on India's 2025 Bihar assembly election does describe AI-generated voice clones and synthetic video circulating during the campaign, but the sourcing available does not trace that activity to Dragonbridge/Storm-1376 or any other PRC-attributed operator specifically -- domestic political actors and other sources are at least as plausible an explanation, and we did not find a primary source making the PRC linkage. We're reporting this the way the evidence actually sits: Microsoft's warning that India is a target is a primary-source claim and stands as one; a specific confirmed India operation is not yet publicly documented, and treating the Bihar deepfakes as proof of it would be exactly the kind of unsupported leap this post is trying to avoid elsewhere.
Knowledge distillation and agentic reconnaissance
Beyond influence operations, China's state cyber apparatus is actively deploying AI across capability development and technical reconnaissance on two fronts:
- AI free-riding via knowledge distillation: As analyzed in FlagThis's coverage of PLA AI strategy, Chinese defense research institutes systematically execute teacher-student knowledge distillation against frontier Western models (including OpenAI GPT models and Anthropic Claude) via API queries. By querying Western models on complex reasoning and military/technical tasks to train compact domestic student models, Chinese state entities extract capabilities while bypassing Western compute and GPU export controls.
- Agentic post-compromise automation: Modern Chinese-speaking threat clusters are actively integrating Agentic AI frameworks. Recent campaigns by UAT-10147 demonstrate the deployment of autonomous AI workflows to direct post-compromise reconnaissance and lateral movement via Microsoft IIS/BadIIS servers and deploy modular SPECTRE implants.
Taking over the account: the mechanics of impersonation and inbox theft
Everything in this post so far has treated "access" as a single category. It isn't. Breaching a network is one thing; taking over a specific person's email or messaging account -- and then using that account, with its existing trust and contact list intact, to impersonate them -- is a different and in some ways more dangerous capability, because the victim's own contacts have no reason to distrust a message that arrives from an address they've corresponded with for years. This is where the clearest, most technically detailed evidence in this investigation sits, and almost all of it points at one target community: Tibetan institutions headquartered in India.
FriarFox, February 2021, is the cleanest documented case. Proofpoint's Threat Research team tracked TA413 (the cluster FlagThis's own database groups under LuckyCat) sending phishing emails that impersonated the Tibetan Women's Association -- sent from a TA413-controlled Gmail account that itself impersonated the Bureau of His Holiness the Dalai Lama, which is headquartered in Dharamshala, India. Victims who engaged were pushed to install a customized, malicious Firefox extension -- built by modifying the legitimate open-source "Gmail Notifier" extension and disguised as an Adobe Flash utility -- that gave the attacker's operators the ability to search, read, label, delete, forward, and archive the victim's Gmail, receive the victim's Gmail notifications, and send mail from the compromised account. That last capability is the point: this isn't just data theft, it's a machine for turning one compromised account into a trusted platform for phishing the next victim, and a companion JavaScript payload pulled in the Scanbox reconnaissance framework to profile the victim's system further. It's a complete, self-contained impersonation-and-propagation loop, and it's built specifically around an organization physically resident in India.
The commercial version of the same idea is now a documented, productized tool. The KnownSec leak (first reported late October 2025) describes a tool called Un-Mail, purpose-built for exactly this: covert email account takeover via IMAP/POP mailbox replication, which silently mirrors a victim's entire inbox to an attacker-controlled server on an ongoing basis and is specifically engineered to survive password changes and multi-factor-authentication prompts, because legacy mail protocols frequently bypass MFA entirely. A companion tool, GhostX, adds browser exploitation, routing manipulation, and credential theft. The same leak's target database explicitly names India as one of the regions it maps in depth (more on exactly what it maps in the next section) -- meaning the firm that built this account-takeover tooling has also built an India-specific target list to point it at.
Citizen Lab's April 2026 report, "Tall Tales," produced with the International Consortium of Investigative Journalists, documents two further clusters assessed as aligned with the PRC running impersonation-driven account takeover against journalists and Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists. GLITTER CARP (active since around October 2024) impersonates known individuals directly -- one Uyghur activist received messages impersonating a well-known Uyghur film director -- and spoofs organizations wholesale, including a fake ICIJ sender domain (icjiorg[.]org) used to invite targets to fictitious interviews. SEQUIN CARP (active since June 2025) went a step further technically, using OAuth token theft rather than password harvesting against ICIJ journalist Scilla Alecci and others -- a technique that leaves no compromised password for the victim to reset, because the attacker holds a live authorization token the platform itself considers legitimate. The report doesn't name Dharamshala specifically, but it's worth being explicit about the geography anyway: its Tibetan-side research partner, TibCERT (the Tibetan Computer Emergency Readiness Team), is itself headquartered in Dharamshala alongside the Central Tibetan Administration it protects.
TibCERT's own reporting, separately, documents two more 2025 campaigns and one genuinely new capability class. Working with Zscaler ThreatLabz, TibCERT identified Operation GhostChat and Operation PhantomPrayers, timed to the Dalai Lama's 90th birthday on July 6, 2025: GhostChat compromised a real Tibetan charity's website and used it to silently redirect visitors to a near-identical fake site, and both operations chained into installs of the Ghost RAT or PhantomNet (SManager) backdoors via fake Tibet-themed apps -- full device compromise, not just an inbox. ThreatLabz attributes both to Chinese state-supported cyber-espionage teams. Separately, on March 14, 2025, TibCERT documented what it assessed as the first confirmed cell-phone-network-level attack on a senior Tibetan leader in exile: the target, nowhere near China at the time, received SMS messages reading "Welcome to China" alongside international-roaming warnings -- consistent with mobile-network-level location spoofing or interception rather than any software compromise on the device itself. That's a capability category distinct from every other technique in this post, and evidence the toolkit against this specific community now extends past phishing and malware into telecom-signaling-level tracking.
This pattern has a fifteen-year paper trail, not a two-year one. The 2009-2010 GhostNet and "Shadow Network" investigations -- the Citizen Lab, SecDev Group, and Munk School of Global Affairs collaboration that first put Chinese state-linked cyber-espionage on the public map -- found that Chinese-based operators had compromised computers inside the Dalai Lama's own office and separately penetrated Indian embassies in Kabul, Moscow, and Dubai, plus India's Military Engineer Services, recovering documents marked SECRET, RESTRICTED, and CONFIDENTIAL, along with roughly 1,500 letters sent from the Dalai Lama's office over an 11-month period. The target set in 2009 -- Tibetan exile institutions headquartered in India, alongside Indian government and diplomatic infrastructure -- is functionally the same target set documented above for 2021 through 2026. This isn't a series of unrelated incidents; it's the same relationship, sustained across a decade and a half, with the tooling upgrading from document theft to full account takeover to telecom-level tracking along the way.
The footholds that don't go away
Some targeting isn't a single campaign -- it's a standing relationship with a target class that gets re-visited every time the tooling improves.
Power grid. RedEcho's original 2021 campaign against Indian Regional and State Load Despatch Centres wasn't a one-off. Recorded Future's follow-up "Continued Targeting" report documents the same infrastructure class -- at least seven State Load Despatch Centres -- getting re-probed in subsequent years using the same ShadowPad-based tradecraft. (Full grading of the RedEcho attribution itself is below.)
Telecom. BSNL, India's state-owned carrier, was breached twice within roughly a year: a December 2023 leak of ~32,000 fibre/landline subscriber records by a seller using the handle "Perell," and an April-May 2024 incident exposing 2.9 million records (278 GB) sold on the dark web for $5,000. Attribution to a Chinese state actor for either BSNL incident specifically is not established -- "Perell" is a dark-web data broker, not an attributed nation-state cluster -- but it sits inside a documented global pattern: Salt Typhoon has been actively exploiting unpatched Cisco IOS XE devices (CVE-2023-20198 and CVE-2023-20273) in telecom carriers worldwide, and Recorded Future's February 2025 reporting names India, alongside the US and South America, among the regions where Salt Typhoon targeted vulnerable Cisco edge infrastructure.
Biometric and identity data fusion. This is still the most consequential foothold in strategic terms, and nothing found this session changes that assessment. Three datasets, independently sourced, combine into population-scale visibility: I-Soon's 95.2 GB Bureau of Immigration haul (entry/exit records), the UIDAI/Aadhaar access the TAG-28 cluster is assessed to have obtained (graded below), and the 815 million-record Aadhaar/passport dataset a seller using the handle "pwn0001" listed on BreachForums in October 2023 for $80,000, discovered by Resecurity. Combined, this gives whoever holds all three a way to cross-reference identity, biometrics, and physical movement for a large fraction of India's population -- exactly the kind of fused dataset that turns bulk PII theft into an intelligence-targeting tool rather than a privacy incident.
Trusted cloud infrastructure as a blind spot. The newest twist, described in the active-campaigns section below, is Mustang Panda using Zoho WorkDrive -- a platform India's own government departments use and trust -- as a live command-and-control channel. This matters structurally: network defenses built around "foreign infrastructure is suspicious, domestic/trusted SaaS is fine" stop working the moment an operator can host C2 traffic inside a vendor the target already whitelists.
Defense and telecom. RedFoxtrot, attributed to PLA Unit 69010 (based in Urumqi), maintains a standing presence against Indian aerospace, defense-contractor, and telecom targets using a mix of bespoke and shared Chinese-APT tooling (Icefog, PlugX, Poison Ivy, PCShare) -- traditional military-intelligence collection rather than the infrastructure pre-positioning or data-harvesting patterns described elsewhere in this section.
Recruitment as a foothold. The Observer Research Foundation's analysis of China's digital espionage playbook documents PRC intelligence services using LinkedIn, Indeed, and Upwork "consultant" personas to cultivate current and former Indian officials, military and intelligence personnel, and Indo-Pacific policy analysts -- initial professional-sounding exchanges that escalate into paid requests for "non-public information" or "strategic assessments." It's a human-layer access vector that shows up in zero malware telemetry and is easy to miss if defensive attention stays entirely on network logs.
What China does with what it takes
The user question behind this section is the harder one: once China has an inbox, a biometric database, or a target's employment history, what actually happens next? Most of this post documents access. This section documents use -- and is honest about where the public evidence for "use" runs out.
Zhenhua Data and the OKIDB profile of 10,000 Indians. In September 2020, a leaked database from Shenzhen Zhenhua Data Information Technology Co. -- a company with reported ties to China Electronics Corporation, a state-owned military-research conglomerate -- surfaced what the company itself called its "Overseas Key Information Database" (OKIDB): profiles on roughly 2.4 million individuals worldwide, including an estimated 10,000 Indians, documented across reporting by India TV News and the Zhenhua Data leak archive. Named entries included Prime Minister Narendra Modi, President Ram Nath Kovind, then-Chief of Defence Staff General Bipin Rawat, Congress leader Sonia Gandhi, former Prime Minister Manmohan Singh, then-Chief Justice of India Sharad Bobde, Supreme Court judge A.M. Khanwilkar, the Lokpal, and the Comptroller and Auditor General -- plus bureaucrats, scientists, journalists, and activists further down the list. Zhenhua's own product materials describe continuously tracking each profiled individual's digital footprint across social media, feeding an "information library" that also ingests news coverage, forum posts, patents, and recruitment listings. India formally raised the matter with China's ambassador. It's worth being precise about the collection method here: this is overwhelmingly open-source scraping, not hacking -- but that's exactly why it belongs in this section rather than the account-takeover one above. The strategic value isn't in any single record; it's in continuous, aggregated tracking of specifically the several thousand Indians whose access, rank, or influence make them worth tracking at all, which is a targeting function, not a privacy incident.
KnownSec's TargetDB makes the fusion logic explicit, in the contractor's own words, and it names India specifically. The leaked target database includes India-tagged datasets cataloged under names like o_data_telecom_info_india (phone numbers, IMSI/IMEI device identifiers, subscriber addresses), o_data_facebookuserinfo_in (scraped Facebook identity data), and commercial datasets covering Royal Enfield motorcycle owners and Indian insurance policyholders. DomainTools' technical analysis of the leak states plainly that linking "breached credentials, phone numbers, and identity documents to technical infrastructure" fuels "spearphishing campaigns, targeted malware delivery," and assesses that this "mirrors Beijing's intelligence interest in India's digital ecosystem" by supporting "identity correlation or demographic profiling." This is, in effect, the contractor's own internal description of exactly the fusion pipeline the "biometric and identity data fusion" foothold described in the abstract above -- here it's dated, sourced to named datasets, and confirmed by the vendor's own leaked documentation rather than inferred.
Where this converts into direct economic advantage: the vaccine intrusions. In March 2021, cyber-intelligence firm CyFirma reported that APT10 (also tracked as Stone Panda or menuPass, and under U.S. indictment since 2018 for MSS-directed operations) had breached the IT systems of the Serum Institute of India and Bharat Biotech -- the two manufacturers, respectively, of India's Covishield and Covaxin COVID-19 vaccines -- by identifying weaknesses in public-facing web servers and supply-chain software. CyFirma's CEO assessed the motive as "exfiltrating intellectual property and getting a competitive advantage over Indian pharmaceutical companies," not disruption. This is the cleanest example in this dossier of stolen access converting directly into commercial and strategic advantage rather than surveillance value.
What we can't confirm, and the case that sets the bar for what "confirmed" would look like. The obvious next question is whether any of this fused data -- Zhenhua's profiles, KnownSec's telecom-and-identity correlations, the UIDAI/ICMR/Bureau of Immigration troika described earlier -- has been used to expose, track, or coerce a specific named Indian individual, the way the LinkedIn-recruitment vector described earlier would predict. We found no publicly documented, confirmed case of that happening to an Indian target. The precedent for what that kind of harm looks like when it is confirmed comes from elsewhere: Foreign Policy reported in December 2020 that China used data stolen in a series of breaches -- including the 2015 Office of Personnel Management hack of over 20 million U.S. federal personnel records -- to help identify and expose undercover CIA officers operating under State Department cover in Africa and Europe, by cross-referencing travel patterns, cover employment histories, and personnel records that no single breach would have revealed alone. That is the demonstrated end state of this kind of data fusion. Nothing at that level of individual, confirmed harm has been publicly documented for an Indian target as of this writing. That absence could mean the underlying activity hasn't happened at the same scale yet, or it could simply reflect that this specific category of outcome -- someone quietly tracked, compromised, or pressured using fused data nobody connects to a single breach -- is exactly the kind of thing that doesn't surface publicly even when it's happening. We're flagging it as the most important open question this investigation didn't resolve, not asserting an answer either way.
What's active right now
Two campaigns tracked in this section were still generating fresh telemetry as of the most recent reporting available -- this is not historical material.
Operation DragonReturn: fake tax utility, live since May 2026
Seqrite Labs disclosed a China-nexus campaign, first observed May 18, 2026, impersonating India's Income Tax Department. The lure is a phishing email directing victims to govtop[.]one/incometax, which serves a ZIP file disguised as the government's own Common_Offline_Utility_ITR-1_to_4_AY2026-27.zip filing tool. Opening it triggers DLL sideloading via a file named nvdaHelperRemote.dll (impersonating a legitimate screen-reader component), which loads a fileless .NET payload with AMSI-bypass logic, then deploys DCRat alongside a Gh0st RAT derivative and an AsyncRAT variant on separate command channels -- redundant C2 so the operation survives losing any single implant to detection.
Targets span individual taxpayers, chartered accountants and tax professionals, corporate finance teams, government contractors, and government-linked tax infrastructure, nationwide. Operational tempo is aggressive: payloads rotated every 7-10 days across at least five distinct variants through May and June 2026, and a June 12, 2026 sample scored 0 out of 66 detections on VirusTotal. As of the most recent confirmation (June 17, 2026), the campaign remained fully active with no sign of slowing.
Seqrite's attribution -- stated as medium-to-high confidence, not certainty -- rests on: Chinese-language web-management-panel strings on the C2 infrastructure; one C2 IP (223.26.63.40) hosted under AS152194 with a Chinese-language "豪凌" admin panel; a second C2 domain (kkxqbh[.]top) resolving to an IP geolocated to Nanchang, Jiangxi Province, under AS4134 (China Telecom's CHINANET backbone); and TTP overlap with the Silver Fox cluster, which has separately been tracked deploying Atlas RAT via weaponized VPN installers. This is a textbook example of how attribution should be communicated -- named, falsifiable technical indicators, an explicit confidence level, no overclaiming.
Full indicator set for defensive use: domains govtop[.]one, ikkkkddd[.]com, kkxqbh[.]top, simaqz.com, jiayingjing.com; C2 endpoints 223.26.63.40:2671 and 117.44.201.119; payload-staging IPs 204.194.48.250, 118.107.0.197, and 27.50.54.191; filenames nvdaHelperRemote.dll, background.jpg/lllyd.jpg (steganographic payload containers), Mixed Reality.exe, and the persistence service MixedSvc. We found no public record of CERT-In coordination on this specific campaign as of this writing -- a gap worth returning to in the detection section below.
SyncFuture: a second, separate group running the same tax-season lure
Operation DragonReturn is not the only Chinese-nexus campaign impersonating India's Income Tax Department right now, and it's worth being precise that this is a second, independently reported operation rather than a restatement of the first. eSentire's Threat Response Unit reported (published January 23, 2026) a campaign first observed in early December 2025 -- five months before DragonReturn -- using phishing emails warning of "tax compliance deficiency" and penalty notices, leading to malicious ZIP downloads. Rather than DCRat, this campaign repurposes SyncFuture TSM (Terminal Security Management), a legitimate commercial endpoint-management product built by Nanjing Zhongke Huasai Technology Co., Ltd, turning it into a full surveillance framework through configuration abuse rather than novel malware development. Attribution evidence differs from DragonReturn's: multiple valid code-signing certificates spanning 2019-2024, kernel drivers signed by "Nanjing Yangtu Information Technology Co., Ltd," and configuration files referencing "Yangtu" infrastructure -- Chinese corporate signing chains rather than Chinese-language admin panels. Whether SyncFuture and DragonReturn are two independent China-nexus clusters that separately converged on the same seasonal lure, or two contractors drawing on the same target list, isn't resolved by either vendor's public reporting. The more useful takeaway for defenders either way: India's tax-filing season is now demonstrably being run as an attack surface by more than one distinct operator at the same time, using different tooling.
Mustang Panda's Zoho WorkDrive campaign: live inside government networks
Acronis's Threat Research Unit disclosed a new Mustang Panda implant set on June 29, 2026, with active beaconing observed June 12-22, 2026. Three new tools: SHARDLOADER, a DLL-sideloading loader delivered via legitimately signed binaries (Solid PDF Creator, Citrix Receiver); MINIRECON, a reworked TONESHELL variant beaconing over WebSocket-over-HTTPS; and ZOHOMURK, which uses hardcoded Zoho OAuth credentials to turn Zoho WorkDrive itself into the command channel.
Acronis confirmed live compromises inside Indian government networks, including machines belonging to senior administrative staff, and -- unusually for this dossier -- worked directly with CERT-In on notification and remediation. Targeting spans government offices, the hydropower sector, and cross-border policy institutions with Taiwan-linked MOUs. The hydropower targeting is not incidental context: it lines up directly with the live India-China standoff over Himalayan dam-building, where China's Yarlung Tsangpo mega-hydropower project in Tibet and India's counter-investment in Arunachal Pradesh dam capacity are both active points of friction.
Attribution evidence: reused Mustang Panda infrastructure, TONESHELL code-family overlap, and -- the kind of small, boring detail that makes attribution credible rather than performative -- a recurring implementation typo, "RunOnece" instead of "RunOnce," across multiple implant samples. Naming for this cluster is fragmented across vendors (Mustang Panda, TA416, Hive0154, Bronze President, Earth Preta, RedDelta), the same kind of vendor-naming sprawl that shows up across most tracked Chinese APT clusters -- worth flagging rather than picking one name and implying it's settled.
A companion campaign in April 2025 saw Acronis attribute the LOTUSLITE backdoor, delivered via the same cloud-staging tradecraft, to intrusions against India's banking sector and South Korean policy circles. And the same wider cluster (tracked by IBM X-Force as Hive0154) has, as of mid-2025, fielded a new air-gap-jumping tool -- SnakeDisk, a USB worm geofenced to fire only on Thailand-based IP addresses, dropping a backdoor called Yokai, alongside an updated Toneshell9. SnakeDisk has not been observed firing against India. We're flagging it anyway because this is the same actor that already breached an air-gapped network via USB self-propagation once before (Camaro Dragon's WispRider, 2023) -- it's a capability class actively being refined, aimed at the same broad target set India's Maya OS/SAMBHAV indigenization push is trying to defend.
The stealth side of that toolkit is being upgraded on the same track. On August 14, 2026, Kaspersky reported via Securelist that Mustang Panda had added a signed kernel-mode rootkit (msagent.sys) to its CoolClient backdoor -- a Windows driver installed as a service that hides the malware's processes, files, and registry keys and filters its C2 network traffic, driven through IOCTL calls. The driver rides a code-signing certificate valid only from August 2013 to September 2014, issued to Nanjing Ranyi Technology Co., Ltd, which Windows still honors at the kernel trust boundary -- the same expired-corporate-certificate abuse pattern that shows up in the SyncFuture reporting above. Kaspersky's named victims are in Myanmar, Mongolia, Pakistan, and Russia, not India; it is included here for the same reason as SnakeDisk -- a documented stealth escalation by an actor with an active, confirmed India operation.
The rest of the 2025-2026 picture
Not every recent Chinese-nexus campaign checked out as India-specific, and it's worth saying so rather than folding everything China-related into the India narrative:
- Tata Electronics (June 2026). A ransomware/extortion crew called World Leaks -- a rebrand of Hunters International -- posted 204,341 files (630 GB) from Tata Electronics to its leak site on June 12, 2026 (covered in FlagThis's supply chain tracking), including files described as Apple component designs, a Tesla vehicle-program engineering drawing set, and staff passport scans; Apple has confirmed it is investigating. Press coverage has floated a Salt Typhoon link, largely on the strength of Salt Typhoon's general China-nexus reputation and the sensitivity of the stolen data. We assess this attribution as unconfirmed and should not be repeated as fact: World Leaks/Hunters International operates as a criminal ransomware-as-a-service and extortion brand, a fundamentally different actor category from a PLA/MSS-linked espionage APT, and we found no technical forensic linkage published connecting the two. The breach itself is real and serious; the Salt Typhoon label attached to it is not yet supported.
- UNC5221/Ivanti mass-exploitation (2025). This China-nexus cluster weaponized CVE-2025-0282 and CVE-2025-22457 in Ivanti Connect Secure and EPMM appliances, deploying the SPAWNCHIMERA malware suite against government, telecom, finance, and legal targets across 12 named countries (UK, US, Austria, Australia, France, Spain, Japan, South Korea, Netherlands, Singapore, Taiwan, UAE). India is not in the confirmed victim list we found. We're including it anyway as a straightforward risk item: Ivanti Connect Secure and EPMM are widely deployed in Indian government and public-sector-undertaking networks, and this is a "check your patch level" recommendation, not a claimed incident.
- RedNovember/TAG-100 (June 2024-July 2025). Recorded Future's Insikt Group tracked this cluster (Microsoft overlaps it with Storm-2077) deploying a Go-based backdoor called Pantegana plus Cobalt Strike and SparkRAT against government and defense targets, heaviest in the US, Taiwan, South Korea, Japan, and — in an April 2025 wave — more than 30 Panamanian government organizations. India does not appear in Recorded Future's published victim breakdown. Included here only as doctrine/tooling context: it's the same edge-appliance-exploitation methodology described in the router-focused advisory below, run by a cluster that has not, on current public evidence, turned that methodology on India specifically.
- The router/edge-device shift, structurally. The joint CISA/NSA/FBI advisory AA25-239A (August 27, 2025, co-sealed by partner agencies including Australia's ACSC) names Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor, and attributes their tooling supply chain to three named Chinese companies -- Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology -- that the advisory says sell offensive capability directly to PLA and MSS units. The core TTP described is compromising edge and backbone routers and SOHO/IoT devices, not servers, for durable, hard-to-attribute persistence -- the direct evolution of the DVR/IP-camera and TP-Link router (Horse Shell) tradecraft documented against India's power sector years earlier. We could not confirm the advisory names India explicitly (the full advisory text was not accessible to us at the time of writing); we're including its TTP description because it matches, closely, tradecraft already documented against Indian infrastructure.
- Operation FlightNight (March 2024). EclecticIQ documented a campaign against Indian government entities (electronic communications, IT governance, national defense) and private energy companies, delivered via a phishing email disguised as an Indian Air Force invitation letter carrying a modified HackBrowserData infostealer -- a related wave was separately tracked by Cyble and Gurucul as "GO Stealer," using an SU-30 fighter-jet procurement-themed lure. The operator exfiltrated 8.81 GB of data -- financial documents, employee personal information, and details of oil-and-gas drilling activity -- via Slack channels used as a covert exfiltration point, and EclecticIQ assessed with medium confidence that the stolen data could enable further intrusions into Indian government infrastructure. Attribution to China was not established by EclecticIQ or subsequent reporting -- the actor is described only as "uncategorized." It's included here anyway because the mechanism -- an impersonated defense-ministry lure, and stolen data explicitly assessed as fuel for the next intrusion -- is exactly the pattern the rest of this post documents, even where the specific operator remains unidentified.
- A DRDO breach claim that didn't hold up. A 2026 report alleged a fresh breach at India's Defence Research and Development Organisation. India's Ministry of Defence investigated and stated it found no evidence of active intrusion, unauthorized network access, or ongoing data exfiltration; most of the "leaked" material was unclassified, and some of what was being recirculated as new actually dated to a separate 2020-2022 breach. It's a useful case study in claim inflation, and a reminder that not every headline in this space survives an actual investigation -- in either direction.
Where this is actually discussed
The user question behind this research was specific: where are these operations actually being discussed, in something like real time? The honest answer is more limited than "a hacker chat room," and it's worth being precise about what we did and didn't find rather than manufacturing an angle that isn't there.
The closest real match is the I-Soon leak itself -- covered above -- which genuinely is leaked internal chat correspondence, not a technical inference. That's the strongest "we can see them talking about India" evidence that exists in the open-source record.
BreachForums is a real, named forum with a real, dated listing: the 815-million-record Aadhaar/passport dataset, sold there by "pwn0001" in October 2023. Telegram bots -- not forums or chat rooms in the traditional sense -- actively resell Indian PII (Aadhaar, PAN, passport, address data) for roughly ₹2.50 per lookup; this data is understood to originate from institutional breaches generally, and we found no basis to attribute the specific bot operators to Chinese state activity -- worth keeping that distinction clear rather than folding all Indian-data-for-sale activity into the China narrative.
Operation Sindoor (May 2025) deserves a direct correction, because it's the most recent and most heavily hyped India cyber-conflict event, and the loudest claims about it don't attribute to China at all. Following India's missile strikes into Pakistan-administered Kashmir, a wave of hacktivist claims hit Indian networks within hours -- branded Telegram/X accounts like "Mr Habib 404," "P@kistanCyberForce," "KAL EGY 319," and the "#OpIndia" hashtag movement claimed breaches of the PMO, the Election Commission, the Andhra Pradesh High Court, and Indian Army personnel data. CloudSEK's own technical assessment of these claims found most of them did not hold up: the alleged 247 GB National Informatics Centre breach turned out to be publicly available marketing material, defacement claims left no actual footprint on the targeted sites, DDoS disruptions lasted under five minutes, the Election Commission "breach" was recycled 2023 data, and the Army personnel data was assessed with high confidence to be fabricated. Nearly all of that activity was Pakistan-aligned or generically multinational hacktivist noise -- not Chinese.
China's actual, better-documented role in that conflict was different and, frankly, more interesting: China publicly confirmed providing on-site technical support to Pakistan's air force during the four-day conflict, with engineers from the Aviation Industry Corporation of China (AVIC) present. That's a real, acknowledged state-to-state technical relationship -- not a hacktivist chat channel, and not something that should be conflated with the Telegram noise happening in parallel.
Finally, and for completeness: we specifically searched Chinese-language forums with a reputation for offensive-security discussion (kanxue, T00LS, and similar communities) for current, open-source-visible discussion of India targeting, and found none. That's a real limitation of open-source research into this specific question, not evidence of absence -- state-directed contractor operations of the kind I-Soon represents simply don't run through public forums, by design.
Grading the evidence: seven China-attribution claims, checked
This is the section the rest of this post exists to support. Cyberattack attribution is hard, contested, and frequently overstated in both directions -- by governments eager to name an adversary and by researchers whose funding and reputation benefit from a punchy finding. India's own government has, in more than one case below, been notably more cautious in its official findings than the media coverage built on top of preliminary reports. We went back through the primary sources -- original vendor reports, government statements, and, where available, court/investigative findings -- for the claims that anchor most India-China cyber coverage, including the source document that started this project.
| Claim | Verdict | Why |
|---|---|---|
| Mumbai blackout (Oct 2020) was a Chinese cyberattack | Not supported | India's own Union Power Minister stated on record it was human error; two official investigating teams reached the same conclusion. |
| RedEcho/ShadowPad targeted India's power grid | PRC-nexus likely; specific actor unconfirmed | Recorded Future's own report declines to firmly attribute to a named group; ShadowPad is shared across 5+ Chinese clusters. |
| AIIMS hack (Nov 2022) traced to China via IP | Weak, never formally closed out | IP evidence is real but VPN-routed; no published forensic conclusion from Delhi Police/CBI/Interpol ties it to a state actor. |
| TAG-28 breached UIDAI and Times Group with Winnti | Moderate-good attribution, disputed by victims | Solid technical case per Recorded Future; both named organizations publicly denied the claims. |
| I-Soon leak shows India as a named target | Strongest evidence category | Primary-source leaked contracts and chat logs, not inferred from malware. |
| Tata Electronics breach is Salt Typhoon | Not established | Breach is confirmed; the actor is a criminal extortion brand (World Leaks), not a matched APT. |
| Operation DragonReturn / Mustang Panda-Zoho are China-nexus | Well-supported, properly hedged | Vendors state explicit confidence levels and cite specific, falsifiable technical evidence. |
Mumbai, October 2020: the claim India's own government retracted
This is the most consequential correction in this piece, because it's the single most-repeated claim in the entire genre of "China is sabotaging Indian infrastructure" writing -- including the source document behind this post, which describes the blackout as "a psychological weapon designed to project PRC dominance." Here is what actually happened, in sequence. Maharashtra's Energy Minister, Nitin Raut, said in March 2021 -- based on preliminary information -- that the outage was "a cyber attack and it was an act of sabotage." That statement is where most of the enduring "China caused the Mumbai blackout" framing originates, timed to land alongside Recorded Future's RedEcho report the same week. But the investigation didn't stop there: India's Union Power Minister, R.K. Singh, later stated on record that the outage was caused by human error, not a cyberattack. Two separate investigating teams reached that conclusion; one of the teams specifically noted that while cyberattacks against Indian grid infrastructure did occur around that period, they were not linked to the Mumbai grid failure. Tata Power, the affected utility, attributed the actual outage to simultaneous substation tripping at MSETCL's Kalwa and Kharghar substations -- a mundane grid-engineering failure, not sabotage. RedEcho's separate, real targeting of load-despatch infrastructure (graded next) is a documented and serious finding on its own; it simply isn't the same event as the Mumbai blackout, and treating them as one story overstates both.
RedEcho and ShadowPad: real targeting, honestly uncertain attribution
RedEcho's targeting of Indian power-sector infrastructure is well-documented and not in serious dispute: Recorded Future identified a sustained rise, from mid-2020, in the use of ShadowPad command-and-control infrastructure (tracked as AXIOMATICASYMPTOTE) communicating with 10 distinct Indian power-sector organizations, including four of five Regional Load Despatch Centres. What's less commonly repeated is how carefully hedged Recorded Future's own attribution language is: the report states the firm does "not currently believe there is enough evidence to firmly attribute the activity in this particular campaign to an existing public group," and tracks RedEcho as "a closely related but distinct activity group" from APT41/Barium and Tonto Team, despite meaningful infrastructure and TTP overlap with both. The reason attribution stalls at "PRC-nexus" rather than a named actor is structural: ShadowPad itself is shared tooling, used by at least five distinct Chinese state-sponsored clusters, which makes it strong evidence of Chinese origin in general and weak evidence for pinning a specific operator.
One genuinely independent corroborating data point: India's own National Critical Information Infrastructure Protection Centre (NCIIPC) issued its own warning about this activity on February 12, 2021 -- before Recorded Future's public report went live on March 1. That's real signal from an Indian government body, not just a foreign vendor's claim, though it's worth noting plainly that pre-publication coordination between researchers and affected-government CERTs is standard industry practice, so this shouldn't be oversold as a fully independent second discovery.
AIIMS, November 2022: real indicators, no closed forensic finding
The November 2022 ransomware-style attack on AIIMS Delhi -- five of a hundred servers encrypted, outpatient and appointment systems down for days, medical data on 30-40 million patients potentially exposed -- is real and well-documented as an incident. The China attribution rests on IP addresses recovered from the headers of the encryption emails, which geolocated to Hong Kong and China's Henan province. That's a genuine technical artifact, not a fabrication. But it was never enough on its own, and Indian officials and security experts said so at the time: an unnamed government official quoted in Indian press noted a Henan-geolocated IP "could be a Chinese physical server or a virtual server" with no guarantee the operators are physically present there, that attackers routinely route through VPNs specifically to defeat this kind of geolocation, and that "even if the attackers are based in China, it has to be seen whether they can be linked to the Chinese State." Delhi Police, working with the CBI and Interpol, pursued the investigation, but we found no published forensic conclusion formally attributing the intrusion to a Chinese state actor. Treat the IP evidence as a real, useful lead that was never closed out publicly -- not as settled attribution, however often it gets cited as one.
TAG-28, UIDAI, and Times Group: a solid case the named victims dispute
Recorded Future's Insikt Group built a comparatively strong technical case for this one: Winnti malware -- described as tooling "shared exclusively among Chinese state-sponsored groups" -- across at least three distinct Indian organizations, roughly 500 MB of data observed being exfiltrated from Bennett Coleman and Co. Ltd. (Times Group) to malicious infrastructure, and a coherent motive (Times Group's sustained reporting on India-China border tensions made its journalists and pre-publication content a plausible intelligence target). That's a meaningfully more complete evidentiary package than the RedEcho or AIIMS cases above. The caveat that has to sit alongside it: both named victims -- UIDAI, the government agency, and Bennett Coleman/Times Group, the media company -- publicly disputed the report's claims when it was published. That doesn't disprove the finding (reputational and regulatory incentives to deny a breach are real and well-understood), but it's a material fact that gets dropped from most retellings of this story, and it belongs in any honest accounting of it.
Where the evidence is actually strongest, and where it's newest
The I-Soon leak (graded in detail above) remains the strongest single piece of evidence in this entire dossier precisely because it isn't inferential -- it's the contractor's own paperwork. And Operation DragonReturn and the Mustang Panda/Zoho campaign, both still active as of this writing, represent the best-practice end of the attribution spectrum: both source vendors state an explicit confidence level rather than asserting certainty, both cite specific and falsifiable technical evidence (infrastructure geolocation, code-family reuse, a recurring implementation typo), and the Mustang Panda finding is reinforced by direct coordination with CERT-In rather than resting on the vendor's word alone. If there's a template for how this category of claim should be communicated going forward, that's it.
Not one-directional
Two things belong here for intellectual honesty, without diluting the substance above: China's Foreign Ministry has, predictably, denied all of this. Spokespeople have called Indian and Western attribution claims "highly irresponsible" and made "with no sufficient evidence," and have separately asserted China is itself "the biggest victim" of hacking activity globally. This is boilerplate -- China issues functionally the same denial in response to attribution claims from every country that makes one, which means it's worth recording but carries no evidentiary weight of its own.
More substantively: this is not a one-directional relationship. SideWinder, an APT assessed with moderate-to-good confidence (hardcoded Asia/Kolkata timezone artifacts in its phishing backend code, plus a consistent targeting pattern dating to 2012) to be of Indian origin, has spent over a decade running espionage operations against Pakistan, Afghanistan, China, and Nepal, and has expanded since 2024 into maritime and logistics targets across South and Southeast Asia, the Middle East, and Africa. Chinese state-linked security firms make their own version of this argument -- researchers at 360 Security Technology have publicly claimed India has become "a major source of cybersecurity threats" to China. None of this changes the strategic asymmetry -- China's documented campaign against India is larger, better-resourced, and targets more consequential infrastructure (power grids, biometric national ID systems, defense contractors) than anything documented in the other direction -- but a reader should know this is a genuine two-way state-sponsored conflict, not a story of a purely passive victim.
It's also worth noting a pattern visible across nearly every case graded above: India's own government has been consistently more cautious about formal, public, named attribution to China than the media coverage built on top of preliminary reports or foreign vendor findings. The Mumbai and AIIMS cases are the clearest examples -- both show a gap between what got widely reported as settled and what India's own investigating authorities were actually willing to state on the record.
Detection engineering: YARA, Sigma, and SaaS C2 hunting
To defend against China-nexus initial-access pipelines and SaaS command channels, security operations centers (SOCs) can deploy these detection artifacts across endpoint EDR, SIEM, and network sensors:
1. Sigma Rule: Detecting Signed Binary DLL Sideloading in User Directories
Detects legitimately signed binaries (e.g. Solid PDF Creator, Citrix Receiver, NVDA screen reader) executing from user-writeable directories (AppData, Temp, Downloads) accompanied by unauthorized DLL drops:
title: Potential DLL Sideloading via Legitimate Signed Utilities
id: a9d8213e-32ef-4e89-8d14-3a9d701e8284
status: experimental
description: Detects execution of known signed utilities used by Mustang Panda and DragonReturn in non-standard user-writeable directories.
author: FlagThis Detection Engineering
date: 2026-08-22
logsource:
category: process_creation
product: windows
detection:
selection_binaries:
Image|endswith:
- '\SolidPDFCreator.exe'
- '\Receiver.exe'
- '\Mixed Reality.exe'
- '\nvda.exe'
selection_paths:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
- '\Downloads\'
condition: selection_binaries and selection_paths
falsepositives:
- Portable installations of legitimate developer tools
level: high
tags:
- attack.defense_evasion
- attack.t1574.002
2. YARA Rule: Detecting Mustang Panda ZOHOMURK & Typo Artifacts
Identifies binary samples belonging to the Mustang Panda / Hive0154 toolset utilizing Zoho WorkDrive OAuth endpoints and the recurring RunOnece implementation typo:
rule APT_MustangPanda_ZOHOMURK_OAuth_C2 {
meta:
description = "Detects Mustang Panda ZOHOMURK backdoor using Zoho WorkDrive as C2"
author = "FlagThis Research"
reference = "https://flagthis.com/posts/china-cyber-india"
date = "2026-08-22"
threat_actor = "Mustang Panda / TA416 / Hive0154"
strings:
$typo = "RunOnece" ascii wide nocase
$zoho_api1 = "workdrive.zoho.com" ascii wide nocase
$zoho_api2 = "accounts.zoho.com/oauth/v2/token" ascii wide nocase
$cmd_file = "command.txt" ascii wide
$res_file = "result.txt" ascii wide
$ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" ascii
condition:
uint16(0) == 0x5A4D and
(
$typo or
(2 of ($zoho_api*) and ($cmd_file or $res_file))
)
}
3. Suricata Rule: Anomalous Non-Browser Zoho WorkDrive API Traffic
Detects programmatic, automated API calls to Zoho WorkDrive endpoints originating from non-standard user agents or anomalous intervals:
alert http $HOME_NET any -> $EXTERNAL_NET any ( \
msg:"FLAGTHIS MALWARE - Possible Mustang Panda ZOHOMURK C2 Activity via Zoho API"; \
flow:established,to_server; \
http.host; content:"workdrive.zoho.com"; endswith; \
http.uri; content:"/api/v1/workdrive/files"; \
http.method; content:"GET"; \
http.user_agent; content:!"Mozilla"; content:!"Chrome"; content:!"Safari"; \
threshold: type both, track by_src, count 5, seconds 60; \
classtype:trojan-activity; sid:2026082201; rev:1; \
)
What Indian defenders should actually watch for
Grounded specifically in the TTPs documented above, not generic advice:
- DLL sideloading via signed binaries is the single highest-leverage detection gap right now. Both live 2026 campaigns -- Operation DragonReturn (via a fake NVDA screen-reader helper DLL) and the Mustang Panda/Zoho campaign (via Solid PDF Creator and Citrix Receiver) -- use the identical initial-access pattern: a legitimately signed executable side-loading a malicious DLL. Application allowlisting plus monitoring for unexpected DLL loads alongside known-signed binaries would catch both campaigns with one control.
- Trusted-SaaS C2 abuse needs its own detection logic. ZOHOMURK's use of Zoho WorkDrive as a command channel was caught specifically because Acronis flagged workstations making Zoho API calls with non-browser user agents and abnormal timing patterns. Any organization that whitelists Zoho, Google Workspace, or similar platforms at the network layer should be doing behavioral monitoring on top of that whitelist, not instead of it.
- Tax season is now a named attack surface. Operation DragonReturn specifically targets chartered accountants, corporate finance teams, and taxpayers with fake ITR filing utilities. Security awareness campaigns timed to filing deadlines, and a standing reminder that the offline ITR utility should only ever be downloaded from
incometax.gov.in, would directly blunt this campaign's primary lure. - Patch Ivanti Connect Secure and EPMM now if you haven't. CVE-2025-0282 and CVE-2025-22457 are both under active China-nexus exploitation globally via UNC5221; Ivanti's footprint in Indian government and PSU networks makes this a live, actionable gap independent of whether India shows up in a public victim list yet.
- Router and edge-device firmware integrity checking belongs in critical-infrastructure networks, not just endpoint AV. The AA25-239A advisory's core finding -- that Chinese state-linked operators now favor compromising SOHO routers, DVRs, and IoT devices over servers for durable C2 -- is a direct continuation of tradecraft already used against India (Horse Shell on TP-Link routers, DVR/IP-camera C2 for ShadowPad). Firmware hash verification and unexpected-outbound-connection monitoring on edge devices deserves the same priority as workstation EDR in power-sector and telecom-adjacent networks.
- Publish the DragonReturn indicators for hunting. Domains
govtop[.]one,ikkkkddd[.]com,kkxqbh[.]top,simaqz.com,jiayingjing.com; IPs223.26.63.40,117.44.201.119,204.194.48.250,118.107.0.197,27.50.54.191; filenamesnvdaHelperRemote.dll,Mixed Reality.exe; service nameMixedSvc. - Close the public-attribution gap. CERT-In issues frequent generic advisories -- 959 alerts, 72 named advisories, and 360 vulnerability notes in 2024 alone -- but we found no CERT-In advisory naming a current Chinese APT campaign specifically, even for the two live campaigns documented in this post. NCIIPC's February 2021 RedEcho warning shows the institutional capability to do this exists; it's an outlier rather than the norm, and closing that gap would shorten dwell time for defenders industry-wide who currently rely on foreign vendor blog posts to learn their own government networks are compromised.
- Track Maya OS and SAMBHAV as unfinished, not solved. The indigenous-OS pivot away from Windows is a structurally sound response to malware families (PlugX, ShadowPad, Winnti) that are overwhelmingly Windows-specific -- but as of the most recent public reporting available, only the Navy has approved Maya OS for deployment; the Army and Air Force remain in evaluation. This is a live gap in the defensive posture, not a completed mitigation.
Timeline
Every row links to the specific document or report that dated fact is sourced to -- not a general "Sources" list at the bottom, but the actual claim-to-citation pairing, so any row can be independently checked.
| Date | Event | Source |
|---|---|---|
| Dec 2003 | "Three Warfares" doctrine formally adopted by the CCP Central Committee and Central Military Commission | Wikipedia, "Three warfares" |
| Mid-2017 | Doklam standoff; PLA runs media/psychological operations against India | Wikipedia, "Three warfares" |
| May 2020 | Galwan Valley clashes trigger the current phase of India-China cyber targeting | Wikipedia, "2020 China–India skirmishes" |
| Sep 2020 | Zhenhua Data leak surfaces OKIDB profiles on ~10,000 Indians, including the PM, President, and CDS | India TV News |
| Feb 2021 | TA413/LuckyCat deploys the FriarFox malicious Firefox extension for Gmail account takeover against Tibetan targets | Proofpoint |
| Feb 12, 2021 | NCIIPC independently warns of RedEcho activity against the power grid | Oneindia News |
| Mar 1, 2021 | Recorded Future publishes the RedEcho report | Recorded Future |
| Mar 2021 | Maharashtra minister Nitin Raut calls the Oct 2020 Mumbai blackout a cyberattack (preliminary) | Tribune India |
| Mar 2, 2021 | Union Power Minister R.K. Singh tells Parliament the Oct 2020 Mumbai blackout was human error, not a cyberattack | Deccan Herald |
| Mar 2021 | CyFirma reports APT10 breached Serum Institute of India and Bharat Biotech for vaccine IP | BusinessToday |
| Mid-2021 | TAG-28 intrusion into UIDAI and Times Group (Winnti) | Recorded Future |
| Apr 2022 | Recorded Future documents continued RedEcho/ShadowPad targeting of Indian SLDCs | Recorded Future |
| Nov 2022 | AIIMS server hack | Indian Express |
| Jan-May 2023 | Camaro Dragon deploys Horse Shell (TP-Link routers) and WispRider (USB self-propagation) | Check Point Research |
| Oct 2023 | ICMR/Aadhaar dataset (815M records) listed on BreachForums by "pwn0001" | Resecurity |
| Feb 2024 | I-Soon leak published on GitHub | Wikipedia, "I-Soon leak" |
| Mar 2024 | Operation FlightNight hits Indian government and energy targets via a fake Air Force invite (attribution to China not established) | EclecticIQ |
| Apr 19, 2024 | PLA dissolves the Strategic Support Force; creates Cyberspace Force and Information Support Force | Jamestown Foundation |
| Oct 2024 | GLITTER CARP impersonation/account-takeover campaign begins (per Citizen Lab's later dating) | Citizen Lab |
| Mar 2025 | DOJ indicts 12 individuals tied to I-Soon and MPS | U.S. Department of Justice |
| Mar 14, 2025 | First confirmed cell-network-level attack on a Tibetan leader in exile | Phayul |
| Apr 2025 | Acronis attributes LOTUSLITE to a Mustang Panda campaign against Indian banking | Acronis TRU |
| May 2025 | Operation Sindoor; hacktivist noise (mostly Pakistan-aligned) vs. China's confirmed technical support to Pakistan's air force | CloudSEK |
| Jun-Jul 2025 | SEQUIN CARP begins; Operations GhostChat and PhantomPrayers hit the Tibetan community ahead of the Dalai Lama's 90th birthday | Zscaler ThreatLabz |
| Aug 27, 2025 | CISA/NSA/FBI advisory AA25-239A on router-focused Chinese state-sponsored operators | CISA |
| Oct-Nov 2025 | KnownSec leak exposes Un-Mail/GhostX account-takeover tooling and an India-tagged TargetDB | DomainTools Investigations |
| Dec 2025 | SyncFuture campaign begins, impersonating India's Income Tax Department (separate from DragonReturn) | eSentire |
| Apr 27, 2026 | Citizen Lab publishes "Tall Tales," detailing GLITTER CARP and SEQUIN CARP | Citizen Lab |
| May 18, 2026 | Operation DragonReturn first observed | Seqrite Labs |
| Jun 12, 2026 | Tata Electronics data leaked by World Leaks | TechCrunch |
| Jun 12-22, 2026 | Mustang Panda's Zoho WorkDrive campaign actively beaconing inside Indian government networks | Acronis TRU |
| Jun 29, 2026 | Acronis discloses the Mustang Panda/Zoho campaign | Acronis TRU |
| Jul 6, 2026 | Seqrite Labs discloses Operation DragonReturn | Seqrite Labs |
| Jul 2026 | Supply chain incident at Tata Electronics (Apple component assembly) analyzed | FlagThis |
| Aug 2026 | PLA model distillation & UAT-10147 Agentic AI post-compromise operations documented | FlagThis / FlagThis |
| Aug 14, 2026 | Kaspersky reports Mustang Panda's CoolClient backdoor upgraded with a signed kernel-mode rootkit (2014-expired certificate); victims Myanmar/Mongolia/Pakistan/Russia, not India | Securelist |
The bottom line
The evidence here splits into two piles, and both matter. What's confirmed is substantial on its own: two to three distinct China-nexus operators actively impersonating Indian government services as this piece was written, a fifteen-year documented pattern of account takeover and impersonation aimed at Tibetan institutions headquartered in India, leaked contractor paperwork that names Indian ministries as targets in the hackers' own internal chat logs, and named individuals under U.S. indictment for running parts of the apparatus behind it. What's not confirmed matters just as much: the Mumbai blackout and the AIIMS hack are routinely cited as settled fact and, on their own primary sources, aren't; and no publicly documented case yet ties China's demonstrated ability to fuse Indian telecom, biometric, and identity data to a specific person actually being exposed, tracked, or coerced by it -- the way that same kind of fusion is already documented to have worked against U.S. intelligence officers a decade ago.
That combination is why this is a maintained page rather than a one-time writeup. The confirmed pile keeps growing -- see the revision history below for exactly what's been added since this went up -- and the unconfirmed pile is precisely what a future CERT-In advisory, court filing, or piece of vendor research could resolve one way or the other. We'll fold in whatever comes next rather than leaving this snapshot to go stale.
Sources
- Operation DragonReturn — Seqrite Labs
- Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT — The Hacker News
- Mustang Panda Targets India's Government and Energy Sectors With ZOHOMURK and MINIRECON — Acronis TRU
- Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks — The Hacker News
- Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics — Acronis TRU
- Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm — IBM X-Force
- China-linked Mustang Panda deploys advanced SnakeDisk USB worm — Security Affairs
- HoneyMyte's CoolClient driver: a kernel rootkit signed with an expired certificate — Kaspersky Securelist
- Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach — TechCrunch
- Apple iPhone: Supply Chain Breach via Tata Electronics — FlagThis
- China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions — Recorded Future
- Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group — Recorded Future
- Human error caused Mumbai outage, no role of Chinese hackers: Power minister — Hindustan Times / PressReader
- Mumbai power outage due to human error, not cyber attack, says Union Power Minister R.K. Singh — Deccan Herald
- AIIMS server hack: Seek Interpol help for IP address details, Delhi Police ask CBI — Indian Express
- China-Linked Group TAG-28 Targets India's "The Times Group" and UIDAI (Aadhaar) Government Agency With Winnti Malware — Recorded Future
- 专家称安洵文件内容证实对中国网络行动的猜测 — 博谈网
- 上海安洵资料疑外泄 涉及贩售国内外被骇情资 — RFA 普通话
- 安洵泄密 专家析中共黑客监控及渗透内幕 — 大纪元
- 待价而沽的黑客:中国大规模网络泄露事件暴露了什么? — VOA 中文
- 安洵文件泄露事件 — 维基百科
- Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers — U.S. Department of Justice
- Sanctions on China-Based Hacker and Data Broker — U.S. Department of State
- A Disturbance in the Force: The Reorganization of PLA Command and Elimination of the Strategic Support Force — Jamestown Foundation
- China Removes the PLASSF and Establishes ISF: Implications for India — Observer Research Foundation
- China's Digital Espionage Playbook and the Implications for India — Observer Research Foundation
- East Asia Threat Actors: Same Targets, New Playbooks — Microsoft Security Insider
- PLA Strategic Exploitation of OpenAI and Anthropic Models via Knowledge Distillation — FlagThis
- UAT-10147: Agentic AI-Driven Post-Compromise Operations — FlagThis
- AI campaigns target voters in India's Bihar state election — Rest of World
- Brief Disruptions, Bold Claims: The Tactical Reality Behind the India-Pakistan Hacktivist Surge — CloudSEK
- China Confirms Direct Support to Pakistan During Operation Sindoor War With India — The Researchers
- Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System (AA25-239A) — CISA/NSA/FBI
- Chinese Hackers Breach Asian Telecom, Remain Undetected for Over 4 Years — The Hacker News
- BSNL Data Breach: Dark Web Leak Exposes 2.9 Million Records — The Cyber Express
- PII Belonging to Indian Citizens, Including their Aadhaar IDs, Offered for Sale on the Dark Web — Resecurity
- India-Linked SideWinder Group Pivots to Hacking Maritime Targets — Dark Reading
- India has become a major source of cybersecurity threats in China: security expert — South China Morning Post
- Maya OS: India's New Security Weapon — M9.News
- Crafting India's Response to State-sponsored Cyberattacks — Delhi Policy Group
- TA413 Leverages New FriarFox Browser Extension to Target Gmail Accounts — Proofpoint
- THE KNOWNSEC LEAK: Yet Another Leak of China's Contractor-Driven Cyber-Espionage Ecosystem — DomainTools Investigations
- Tall Tales: How Chinese Actors Use Impersonation and Stolen Narratives to Perpetuate Digital Transnational Repression — The Citizen Lab
- China-linked hackers led phishing campaigns targeting journalists and activists — The Record from Recorded Future News
- Illusory Wishes: China-nexus APT Targets the Tibetan Community — Zscaler ThreatLabz
- First cell-phone network cyberattack on Tibetan leader detected — Phayul
- Tracking GhostNet: Investigating a Cyber Espionage Network — Citizen Lab
- Researchers Uncover 'Shadow Network' — Dark Reading
- Zhenhua Data leak — Wikipedia
- Zhenhua Monitoring India: What China firm's collected data can be used for — India TV News
- China Used Stolen Data to Expose CIA Operatives in Africa and Europe — Foreign Policy
- Chinese state backed hackers attack Serum Institute, Bharat Biotech: cybersecurity firm — BusinessToday
- Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign — eSentire
- Operation FlightNight: Indian Government Entities and Energy Sector Targeted by Cyber Espionage Campaign — EclecticIQ
- Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite — The Hacker News
- The Dragon Who Sold His Camaro: Analyzing Custom Router Implant — Check Point Research
- I-Soon leak — Wikipedia
- Three warfares — Wikipedia