Menu
Browse

Cyber Incident Victim: Government of India

Date:

Mar 2016

Location:

India

Summary

Pakistan-linked hackers conducted a cyber-espionage campaign targeting Indian military personnel through spear-phishing emails exploiting an Adobe Reader vulnerability. The attackers exfiltrated sensitive data including military strategies, tactical movements, training materials, personnel identification documents, salary details, passport scans, taxation records, and private photographs to command-and-control servers in Pakistan. Security researchers uncovered the operation due to inadequate server concealment, enabling full access to malware source code and evidence of planned future attacks involving Android malware against the same targets.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early March 2016, Pakistan-linked hackers initiated Operation C-Major, a cyber-espionage campaign targeting Indian military personnel through spear-phishing emails. The attackers exploited a vulnerability in Adobe Reader to deliver spyware, compromising victims' systems. Security firm Trend Micro identified the campaign after analyzing the malware's infrastructure, noting the attackers failed to fully conceal their command and control server's location in Pakistan. Researchers accessed the malware's complete source code due to the use of easily decompiled programming languages, revealing the operation's exclusive focus on Indian military targets. The server's IP address and data exfiltration mechanisms were traced, confirming the theft of sensitive information.

Cyber Incident Image

Analysis of the compromised servers revealed extensive collections of stolen military data, including personnel identification scans, salary records, passport details, and taxation documents. Private materials such as personal photographs were also exfiltrated. The breach exposed highly classified Indian Army operational information, including tactical movement strategies and training materials. Trend Micro further discovered evidence of a planned follow-up campaign involving Android malware designed to target the same military entities. The attackers' operational security shortcomings enabled researchers to intercept these details, though the involvement of Pakistani state actors remained unconfirmed despite the server's geographical location and the campaign's strategic focus.

Sources
Sources available to members
1 source