On the afternoon of 18 February, a retired army officer received a seemingly innocuous mail. Sent by a serving and senior member of the army, and coming from a respectable ‘gov.in’ address, it was an invitation to a lunch in Delhi. The message was brief, even by military standards, with the details enclosed in an attachment linked within the email.

Unbeknownst to the retired officer, the link was a veritable Pandora’s box. When clicked, it downloaded an app containing an assortment of circulars and news related to the Indian army. That, however, was just an eyewash. Its true purpose was to unleash malware, which would course through the victim’s computer or phone, stealing everything from WhatsApp chats to SMSes and media files. This malware, if left unchecked, could stay on a target’s system indefinitely, constantly pilfering sensitive data. 

According to multiple sources working closely with one of the cyber incident response teams attached to the Ministry of Defence, the data was being transmitted to a command and control centre in the Netherlands—the source of the phishing attack. They told The Ken that hackers made use of the country’s many ‘bulletproof hosting’ services, which essentially allow hackers to securely host malicious content which can be used to carry out cyber attacks. These servers, which were paid for in Bitcoin, were accessed from Karachi, Pakistan.

While media reports have emerged emerged Hindustan Times Ex-defence personnel hit by phishing attack Read more claiming that only a few dozen retired army personnel were targeted, The Ken has learnt that hundreds of Indian army personnel—both serving and former—fell prey to the email. “The data copied included personal images, audio and call recordings, and PDF documents pertaining to troop movements,” say the sources quoted above. If the claim about leaked troop movement documents is true, it indicates that serving personnel were indeed targeted. The Ken put this claim to the Ministry of Defence, but received no response.

Phishing attacks—using fraudulent or manipulated messages to steal information—are nothing new. These attacks have found increased utility in espionage, with a number of countries using hackers to ferret out sensitive information from both rivals and allies.

In this case, hackers first compromised the email credentials of a serving officer and used it to send malware-laden emails to others. Coming from a high-ranked official and from an official ID, few suspected anything was amiss.

Guess who

According to a response in the Lok Sabha from the Ministry of Electronics and Information Technology (MeitY), cyber intrusions in the country could have links with Pakistan, China, North Korea, Russia, and the US, among others.

AUTHOR

Pratap Vikram Singh

Pratap is based out of Delhi and covers policy and myriad intersections with the other sectors, most notably technology. He has worked with Governance Now for seven years, reporting on technology, telecom policy, and the social sector.

View Full Profile

Subscribe to read this story

The Ken is the only business subscription you need. Questions?

 

Premium

  • 5 original and reported longform business stories every week
  • Access to ONLY India edition
  • Close to 250 exclusive stories every year
  • Full access to over 5 years of paywalled stories
  • Pick up to 5 premium subscriber newsletters
  • 4 original and reported longform business stories each week
  • Access to ONLY Southeast Asia edition
  • Close to 200 exclusive stories every year
  • Full access to all paywalled stories since March 2020
  • Pick up to 5 premium subscriber newsletters

Rs. 2,750 /year

$ 120 /year

India Edition
Subscribe Subscribe
Most Asked For

Borderless

  • 8 original and reported longform business stories each week
  • Access to both India and Southeast Asia editions
  • Close to 400 exclusive stories every year
  • Full access to over 5 years of paywalled stories across India and Southeast Asia
  • Unlimited access to all premium subscriber newsletters
  • Visual Stories

Rs. 4,200 /year

Subscribe
 

Echelon

  • 8 original and reported longform business stories each week
  • Access to both India and Southeast Asia editions
  • Close to 400 exclusive stories every year
  • Full access to over 5 years of paywalled stories across India and Southeast Asia
  • Unlimited access to all premium subscriber newsletters
  • Visual Stories
  • Bonus annual gift subscription
  • Priority access to all new products and features

Rs. 8,474 /year

Subscribe
Or

Questions?

What kind of subscription plans do you offer?

We have three types of subscriptions
- Premium which gives you access to either the India or the Southeast Asia edition.
- Borderless which gives you complete access to The Ken across both editions
- Echelon which gives you complete access to The Ken across both editions along with a bonus gift subscription

What do I get if I subscribe?

The Premium edition gives you access to stories in that edition along with any five subscriber-only newsletters of your choice.

The Borderless and Echelon subscription gives you complete access to The Ken across editions and unlimited access to as many newsletters as you like.

What topics do you usually write about?

We publish sharp, original and reported stories on technology, business and healthcare. Our stories are forward-looking, analytical and directional — supported by data, visualisations and infographics. We use language and narrative that is accessible to even lay readers. And we optimise for quality over quantity, every single time.

Our specialised subscriber-only newsletters are written by our expert, award-winning journalists and cover a range of topics across finance, retail, clean energy, cryptocurrency, ed-tech and many more.

How many newsletters do you have?

We are constantly adding specialised subscriber-only newsletters all the time. All of these are written by our team of award-winning journalists on a specialised topic.

You can see the list of newsletters that we publish over here.

Does a Premium subscription to your Indian edition get me access to the Southeast Asia edition? Or vice-versa?

Afraid not. Each edition is separate with its own subscription plan. The India edition publishes stories focused on India. The Southeast Asia edition is focused on Southeast Asia. We may occasionally cross-publish stories from one edition to the other.

We recommend the Borderless or the Echelon Plan which will give you access to stories across both editions.

Do you have a mobile app?

Yes! We have a top-rated mobile app on both iOS and Android which allows you to read on-the-go and has some amazing features like the ability to bookmark stories, save on your device, dark mode, and much more. It’s really the best way to read The Ken.

Is there a free trial?

You can sign up for a free account to experience The Ken and understand our products better. We’ll send you some free stories and newsletters occasionally, and you can access our archive of previously published free stories. You can stay on the free account as long as you’d like.

The vast majority of our stories, articles and newsletters can be accessed only by a paid subscription.

Do you offer any discounts?

Sorry, no. Our journalism is funded completely by our subscribers. We believe that quality journalism comes at a price, and readers trust and pay us so that we can remain independent.

Do you offer refunds?

No. We allow you to sample our journalism for free before signing up, and after you do, we stand by its quality. But we do not offer refunds.

I am facing some trouble purchasing a subscription. What can I do?

Just write to us at [email protected] with details. We’ll help you out.

I have a few more questions. How can I reach out to you?

Sure. Just email us at [email protected] or follow us on Twitter.