Hacking

Users online claim Kudankulam nuclear power plant was hit by a cyber attack

In these hours an alleged cyber attack on the Kudankulam Nuclear Power Plant in Tamil Nadu made the headlines, but the KKNPP denies it.

Worrying news made the headlines, the Kudankulam Nuclear Power Plant (KKNPP) was hit by a cyber attack. Some users are claiming on the social media that a piece of the ‘DTrack’ malware has infected the systems at the KKNPP.

The DTrackmalware was described by Kaspersky in September as a tool that could be used to spy on the victims and exfiltrate data of interest. The malware supports features normally implemented in remote access trojan (RAT). Below a list of some functionalities supported by the Dtrack payload executables analyzed by Kaspersky:

  • keylogging,
  • retrieving browser history,
  • gathering host IP addresses, information about available networks and active connections,
  • listing all running processes,
  • listing all files on all available disk volumes.

The KKNPP is the largest nuclear power plant located at Kudankulam in Tamil Nadu, but personnel at the nuke plant has denied the incident.

“Amid claims on the social media that there has been a cyber-attack on India’s largest nuclear power plant located at Kudankulam in Tamil Nadu, the atomic power station has denied that it has been the target of any such nefarious activity.” reads a post published by the TimesNowNews website.

“In a statement issued on Tuesday, the Kudankulam Nuclear Power Plant (KKNPP) refuted reports of the alleged cyber-attack, calling it ‘false information’. “

KNPP declared that its network is safe and that the control room of the nuclear power plant is not exposed online.

“Any cyber-attack on the Nuclear Power Plant Control System is not possible,” the statement stated categorically.

The news of the attack was initially spread by this Twitter use that reported the malware infection:

According to a report by news agency IANS, one of the two power reactors at the KKNPP had suspended operations due to the alleged cyber attack.

Congress MP Shashi Tharoor called for an explanation from the government authorities.

The reply of the personnel at the nuclear plant is eloquent, the news of the cyber attack is fake.

“Some false information is being propagated on the social media platform, electronic and print media with reference to the cyber attack on Kudankulam Nuclear Power Plant,” R. Ramdoss, training superintendent and information officer at the power plant, said.

“This is to clarify Kudankulam Nuclear Power Project (KKNPP) and other Indian Nuclear Power Plants Control Systems are stand alone and not connected to outside cyber network and Internet. Any cyber attack on the Nuclear Power Plant Control System is not possible,” Ramdoss said. “Presently, KKNPP Unit-1 &2 are operating at 1000 MWe and 600 MWe respectively without any operational or safety concerns.”

“It may be noted here that the second 1,000 MW nuclear power unit at Kudankulam had stopped generating power on October 19. It was reported that the atomic power plant stopped power generation owing to low “SG level”.” concludes The Times Now News.

“The KKNPP, owned by the Nuclear Power Corporation of India Ltd (NPCIL), has two 1,000 MW nuclear power plants. The plants were constructed using Russian equipment.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – KKNPP, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

North Korea-linked APT groups target South Korean defense contractors

The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…

10 hours ago

U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity

The U.S. Department of State imposed visa restrictions on 13 individuals allegedly linked to the…

21 hours ago

A cyber attack paralyzed operations at Synlab Italia

A cyber attack has been disrupting operations at Synlab Italia, a leading provider of medical…

22 hours ago

Russia-linked APT28 used post-compromise tool GooseEgg to exploit CVE-2022-38028 Windows flaw

Russia-linked APT28 group used a previously unknown tool, dubbed GooseEgg, to exploit Windows Print Spooler…

1 day ago

Hackers threaten to leak a copy of the World-Check database used to assess potential risks associated with entities

A financially motivated group named GhostR claims the theft of a sensitive database from World-Check…

2 days ago

Windows DOS-to-NT flaws exploited to achieve unprivileged rootkit-like capabilities

Researcher demonstrated how to exploit vulnerabilities in the Windows DOS-to-NT path conversion process to achieve…

2 days ago

This website uses cookies.