Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

AIIMS cyberattack: Asking the right questions matters

Altszn.com by Altszn.com
January 10, 2023
in Dark Web
0
AIIMS cyberattack: Asking the right questions matters
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


The digitisation of the All-India Institute of Medical Sciences (AIIMS) “represents a sustainable and replicable model for hundreds of India’s hospitals”, argued an AIIMS official when it completely digitised operations in 2016. But as the recent developments surrounding the AIIMS cyberattack have shown, the digitisation project has been anything but “sustainable” or “replicable”.

On November 23, 2022, the e-Hospital application used by AIIMS Delhi to manage appointments and consultations stopped working after the servers on which this application and its database were hosted became the target of a cyberattack. AIIMS shifted all its operations from digital to manual mode, resulting in confusion, long lines, and discomfort to patients. Even as the digital services were gradually restored in December, three sets of serious questions about the cyberattack remain unanswered. 

The first set of questions is about the modus operandi of the attack. Media reports mention that the targeted servers were infected with Wammacry, Mimikatz and Trojan. The term ‘Wammacry’ appears to have been misspelt, as the famous crypto-ransomware is called ‘Wannacry’. Wannacry unleashed havoc globally in 2017 in systems running on Microsoft Windows. Mimikatz is a post-exploitation tool that is used to steal credentials. The term ‘Trojan’ just indicates that Trojan malware was used. But there are many different types of Trojans out there and which one was used is not clear.

On December 16, Rajeev Chandrasekhar, Union Minister of State for Electronics and Information Technology, informed the Rajya Sabha: “As per preliminary analysis, servers were compromised in the information technology network of AIIMS by unknown threat actors due to improper network segmentation, which caused operational disruption due to non-functionality of critical applications”. Chandrasekhar’s statement only throws light on one of the most glaring system-wide vulnerabilities in the AIIMS digital ecosystem: poor network segmentation. A day earlier, his senior minister Ashwani Vaishnav had informed parliament that a hierarchical system is now being put in place in AIIMS.

However, neither statements by government functionaries nor media reports have clearly laid out the following details: Which exact vulnerabilities were exploited by the hackers? Have these vulnerabilities been patched? Were zero-day exploits used by the attackers or were known (but un-patched) vulnerabilities used? For how many days and months were the attackers inside the AIIMS systems before launching their attack?

The next set of questions is about potential actors and motives. Two Protonmail addresses belonging to the attackers have been mentioned in media reports: “dog2398” and “mouse63209”. Two IP addresses have been traced to Hong Kong and Henan province in China. But this limited information is not sufficient to make a reliable attribution. Attackers often route their attacks through different countries. And even if the attackers are based in China, it has to be seen whether they can be linked to the Chinese State or not. Therefore, in terms of attribution, months of careful technical analysis will be needed before anything can be claimed with a reasonable level of certainty.

In terms of motives, the story gets very interesting. The ransom amount has been reported variously to be Rs 4.2 crore and Rs 200 crore. Irrespective of which figure is accurate, it is very low for a ransomware attack of this magnitude. Was it really a ransomware attack? Or was the real motive to steal the sensitive health data of millions of Indians and sell it or use it for nefarious purposes, including demographic intelligence? Or was it to get hands on the health data of certain VVIPs who get treated at AIIMS?

The final set of questions is about patient data. The government has maintained that everything is under control, that services are being restored, and that patient data is being repopulated into the system. But what about the patient data that was encrypted and potentially exfiltrated by the hackers? There is no word about what happened to the compromised data. Has it already made its way to the dark web? Or is it being analysed by a malicious State or non-State actor? Does the government’s obfuscation regarding the fate of the data indicate that it knows the amount of damage this data leak has caused and wants to suppress information from the general public?

While it may be too early to answer some of the questions posed above, it is only timely to raise and discuss them. Otherwise, the same questions will be asked when a cyberattack of an even bigger magnitude crashes or compromises the entire digital health infrastructure which the current government is ambitiously creating under the Ayushman Bharat Digital Mission.

(The writer is a PhD candidate at the National Institute of Advanced Studies, Bengaluru)



Read More: news.google.com

Tags: AIIMScyberattackdark webDarknetin perspectiveMattersquestions
ADVERTISEMENT

Recent

Polygon co-founder steps down, says he can no longer give his best

Polygon co-founder steps down, says he can no longer give his best

May 24, 2025
Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

May 23, 2025
'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

May 23, 2025

Categories

  • Bitcoin (4,653)
  • Blockchain (11,040)
  • Crypto (8,975)
  • Dark Web (486)
  • DeFi (8,216)
  • Ethereum (4,697)
  • Metaverse (7,103)
  • Monero (265)
  • NFT (1,253)
  • Solana (4,963)
  • Web3 (20,186)
  • Zcash (475)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Polygon co-founder steps down, says he can no longer give his best

    Polygon co-founder steps down, says he can no longer give his best

    May 24, 2025
    Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

    Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

    May 23, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 107,209.00
    • ethereumEthereum (ETH) $ 2,497.03
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.29
    • bnbBNB (BNB) $ 661.04
    • solanaSolana (SOL) $ 171.71
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.219210
    • cardanoCardano (ADA) $ 0.735149
    • tronTRON (TRX) $ 0.272681
    • staked-etherLido Staked Ether (STETH) $ 2,492.94
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,995.00
    • hyperliquidHyperliquid (HYPE) $ 35.74
    • suiSui (SUI) $ 3.51
    • wrapped-stethWrapped stETH (WSTETH) $ 2,999.50
    • chainlinkChainlink (LINK) $ 15.18
    • avalanche-2Avalanche (AVAX) $ 22.27
    • stellarStellar (XLM) $ 0.281742
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • bitcoin-cashBitcoin Cash (BCH) $ 414.60
    • leo-tokenLEO Token (LEO) $ 8.86
    • hedera-hashgraphHedera (HBAR) $ 0.184276
    • moneroMonero (XMR) $ 404.38
    • the-open-networkToncoin (TON) $ 2.98
    • litecoinLitecoin (LTC) $ 94.42
    • wethWETH (WETH) $ 2,497.65
    • polkadotPolkadot (DOT) $ 4.46
    • usdsUSDS (USDS) $ 0.999775
    • bitget-tokenBitget Token (BGB) $ 5.39
    • wrapped-eethWrapped eETH (WEETH) $ 2,666.30
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.997096
    • pi-networkPi Network (PI) $ 0.770607
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 0.999450
    • whitebitWhiteBIT Coin (WBT) $ 31.65
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,294.00
    • aaveAave (AAVE) $ 265.72
    • daiDai (DAI) $ 0.999593
    • bittensorBittensor (TAO) $ 421.14
    • uniswapUniswap (UNI) $ 5.99
    • nearNEAR Protocol (NEAR) $ 2.70
    • aptosAptos (APT) $ 5.14
    • jito-staked-solJito Staked SOL (JITOSOL) $ 206.85
    • okbOKB (OKB) $ 52.02
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • ondo-financeOndo (ONDO) $ 0.921491
    • crypto-com-chainCronos (CRO) $ 0.094535
    • ethereum-classicEthereum Classic (ETC) $ 18.09
    • internet-computerInternet Computer (ICP) $ 5.12
    • kaspaKaspa (KAS) $ 0.103577
    • bitcoinBitcoin (BTC) $ 107,209.00
    • ethereumEthereum (ETH) $ 2,497.03
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.29
    • bnbBNB (BNB) $ 661.04
    • solanaSolana (SOL) $ 171.71
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.219210
    • cardanoCardano (ADA) $ 0.735149
    • tronTRON (TRX) $ 0.272681
    • staked-etherLido Staked Ether (STETH) $ 2,492.94
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,995.00
    • hyperliquidHyperliquid (HYPE) $ 35.74
    • suiSui (SUI) $ 3.51
    • wrapped-stethWrapped stETH (WSTETH) $ 2,999.50
    • chainlinkChainlink (LINK) $ 15.18
    • avalanche-2Avalanche (AVAX) $ 22.27
    • stellarStellar (XLM) $ 0.281742
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • bitcoin-cashBitcoin Cash (BCH) $ 414.60
    • leo-tokenLEO Token (LEO) $ 8.86
    • hedera-hashgraphHedera (HBAR) $ 0.184276
    • moneroMonero (XMR) $ 404.38
    • the-open-networkToncoin (TON) $ 2.98
    • litecoinLitecoin (LTC) $ 94.42
    • wethWETH (WETH) $ 2,497.65
    • polkadotPolkadot (DOT) $ 4.46
    • usdsUSDS (USDS) $ 0.999775
    • bitget-tokenBitget Token (BGB) $ 5.39
    • wrapped-eethWrapped eETH (WEETH) $ 2,666.30
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.997096
    • pi-networkPi Network (PI) $ 0.770607
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 0.999450
    • whitebitWhiteBIT Coin (WBT) $ 31.65
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,294.00
    • aaveAave (AAVE) $ 265.72
    • daiDai (DAI) $ 0.999593
    • bittensorBittensor (TAO) $ 421.14
    • uniswapUniswap (UNI) $ 5.99
    • nearNEAR Protocol (NEAR) $ 2.70
    • aptosAptos (APT) $ 5.14
    • jito-staked-solJito Staked SOL (JITOSOL) $ 206.85
    • okbOKB (OKB) $ 52.02
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • ondo-financeOndo (ONDO) $ 0.921491
    • crypto-com-chainCronos (CRO) $ 0.094535
    • ethereum-classicEthereum Classic (ETC) $ 18.09
    • internet-computerInternet Computer (ICP) $ 5.12
    • kaspaKaspa (KAS) $ 0.103577