Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Fears of Renewed Chinese Interest In Hacking Power Grids Stretch Back Two Years
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > Fears of Renewed Chinese Interest In Hacking Power Grids Stretch Back Two Years
Cyber

Fears of Renewed Chinese Interest In Hacking Power Grids Stretch Back Two Years

Concerns regarding a resurgent Chinese focus on hacking power grids date back approximately two years. In February 2021, cybersecurity company Recorded Future raised an alarm, revealing that state-sponsored Chinese hackers had implanted malicious software into power grid systems in nearby India. The breach also extended to railway and seaport networks, and it unfolded against the backdrop of a territorial dispute between the two nations.

Matthew Giannelis
Last updated: September 13, 2023 6:53 am
Matthew Giannelis
Share
SHARE

At the time Recorded Future indicated that the breach seemed to be targeted at acquiring the capability to potentially trigger blackouts in India.

The firm noted that it remained uncertain whether this tactic was primarily intended to convey a message to India or to establish a practical capability in anticipation of potential military conflicts, or possibly a combination of both motivations.

A notorious group of Chinese cyberspies, collectively known as APT41, has gained infamy for orchestrating audacious hacking campaigns tied to China in the last ten years.

Their tactics encompass a wide spectrum, from launching software supply chain attacks that planted malware in popular applications to delving into profit-driven cybercrime, including the brazen theft of pandemic relief funds from the US government. However, it seems that an offshoot of this group has now redirected its focus towards an alarming new target: power grids.

Today, researchers from the Threat Hunter Team at Symantec, a cybersecurity firm under the Broadcom umbrella, unveiled a breach orchestrated by a Chinese hacker group connected to APT41, which Symantec has dubbed “RedFly.”

The breach infiltrated the computer network of a national power grid in an undisclosed Asian country. The intrusion commenced in February of this year and persisted for a minimum of six months, during which the hackers extended their presence across the information technology network of the nation’s principal electric utility.

As of today, there remains a considerable degree of uncertainty surrounding the extent to which these hackers approached the brink of disrupting power generation or transmission.

Dick O’Brien, a principal intelligence analyst on Symantec’s research team says the unnamed country whose grid was targeted in the breach was one that China would “have an interest in from a strategic perspective.

O’Brien points out that Symantec lacks conclusive evidence indicating that the hackers’ primary objective was to disrupt the nation’s power grid. It remains a possibility that their activities were driven by espionage motives.

However, researchers at the cybersecurity firm Mandiant have identified hints suggesting that these hackers could be the same group previously detected targeting electrical utilities in India.

Considering recent alerts regarding Chinese hackers breaching power grid networks in various US states and Guam, with a particular focus on potentially causing blackouts, O’Brien cautions that there is a legitimate basis to suspect that China might be pursuing a similar course of action in this instance.

Accoridng to O’Brien there are all sorts of reasons for attacking critical national infrastructure targets. “You always have to wonder if one of the reasons is to be able to retain a disruptive capability.

“I’m not saying they would use it. But if there are tensions between the two countries, you can push the button.” says O’Brien

Symantec’s discovery emerged in the wake of alerts issued by Microsoft and US government agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA).

These warnings centered on a separate Chinese state-sponsored hacking entity called Volt Typhoon, which had successfully infiltrated US electric utilities, including those in Guam—a US territory.

This intrusion raised concerns of potential cyberattacks, especially in the event of a conflict, such as a military standoff related to Taiwan.

In a subsequent report, The New York Times disclosed government officials’ apprehensions, particularly regarding the possibility of the malware being strategically placed within these networks to enable the disruption of power to US military installations.

There is compelling evidence to suggest that both the 2021 hacking campaign centered on India and the recent breach of a power grid, as identified by Symantec, may have been orchestrated by the same group of hackers with affiliations to the larger network of Chinese state-sponsored cyber operatives, commonly referred to as APT41. APT41 is known by various aliases, including Wicked Panda and Barium.

Symantec points out that the hackers responsible for the power grid intrusion they tracked employed a specific malware called ShadowPad.

The malware was first utilised by a subgroup of APT41 in 2017 during a supply chain attack. The attack involved compromising the code distributed by the networking software company NetSarang. ShadowPad has been deployed in various incidents since then.

In 2020, five individuals believed to be members of APT41 were indicted and identified as operatives working for Chengdu 404, a contractor affiliated with China’s Ministry of State Security.

Notably, as recently as last year, the US Secret Service issued a warning regarding APT41 hackers, who were found to have illicitly acquired millions in US Covid-19 relief funds. This incident marked a rare instance of state-sponsored cybercriminal activity targeting another government.

Over the period of several years China’s state-sponsored hacking endeavors have predominantly revolved around espionage.

Meanwhile, other nations such as Russia and Iran have ventured into endeavors aimed at infiltrating electrical utilities, seemingly with the goal of implanting malware capable of instigating strategic blackouts.

A prime example is the Russian military intelligence group Sandworm, which made efforts to induce three blackouts in Ukraine, achieving success in two of these instances.

Furthermore, a Russian group linked to its FSB intelligence agency, known as Berserk Bear, has repeatedly breached the US power grid to acquire a similar capability. Interestingly, they have refrained from any attempts to provoke disruptions in power supply, despite possessing the means to do so.

ByMatthew Giannelis
Follow:
Secondary editor and executive officer at Tech Business News. An IT support engineer for 20 years he's also an advocate for cyber security and anti-spam laws.
Previous Article How to reduce or lower the spam score of a website - tech news How To Reduce The Spam Score of A Website According To SEO Metrics
Next Article Western Health - Modernisation Program Western Health Transforms Workplace & Patient Care With Bold Modernisation Program
China-Linked Hackers Breached a Power Grid over two years - tech news

Tech Articles

Why your nbn evening speeds slow down

Why Your NBN Slows Down at Night — And How To Find the Real Cause

NBN slow at night? ACCC data shows why evening speeds…

July 2, 2026

How AI Is Changing The Way Businesses Build Websites

Businesses are increasingly using AI website builders such as Lovable,…

August 25, 2026
Online Privacy - Ways to protect your personal information

Want Complete Online Privacy? Disconnecting From the Internet May Be The Only Certain Option

Complete online privacy is becoming increasingly difficult as websites, apps…

August 8, 2026

Recent News

Global scam operation ‘Classiscam’
Cyber

Global scam operation ‘Classiscam’ expanded to Singapore

9 Min Read
Optus allocates $140 million data breach hack
Cyber

Optus $140 million allocation to cover data breach costs

2 Min Read
Australia impose sanctions on North Korean cyber ops -Penny Wong
Cyber

Australia Sanctions North Korean Cybercriminals Funding Weapons Programs

4 Min Read
Cyber

Scammer threatens site owners for backlinks

4 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

September, 18, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?