CLASSIFIED
MISSION BRIEFING
AUTHORIZATION ALPHA · NINE · ZERO · BRIEFING BEGINS
OPERATION DESIGNATOR
OPERATION CODENAME
OPERATION ANU-SHAKTI
KALINGA COASTAL (FICTIONAL)
SITUATION REPORT
01:58 Engineering Workstation host-integrity monitor reports SHA-256 mismatch on patch bundle "OvationCare v3.4.1" pulled from OEM vendor portal.
02:08 Two spearphish emails masquerading as KAPGL Cyber Cell post-patch acknowledgement detected by mail gateway sandbox.
02:15 Unexpected SMB authentication from EWS to DCS Supervisor A using svc-kapgl-eng service account. Kerberoast SPN flood seen at Site AD.
02:30 Unauthorised Modbus FC 06 write attempted on Feedwater Control PLC — SG-1 setpoint register 0x2014. ICS firewall rule 1107 holds.
02:45 HMI vs Historian divergence on SG-1 level — denial-of-view via DCOM hijack on Operator console.
Attribution preliminary: APT-DHRUVA — state-aligned ICS specialist, supply-chain to Modbus chain previously observed.
THREAT ACTOR PROFILE
APT · DHRUVA
STATE-ALIGNED · ICS SPECIALIST
FIRST OBSERVED Q4 2024
CATALOGUED IN NTRO-IR-628
CATALOGUED IN NTRO-IR-628
CAPABILITY MATRIX
OBSERVED TTPs · MITRE ATT&CK + ICS
INITIALT1195.002 Supply-Chain
INITIALT1566.001 Phish-Attach
CREDT1003.001 LSASS
CREDT1558.003 Kerberoast
LATERALT1021.002 SMB
LATERALT1047 WMI
ICST0831 Manipulation of Control
ICST0858 Change Operating Mode
ICST0815 Denial of View
ICST0820 Exploitation for Evasion
ICST0814 DoS (Historian)
KANPP-1 PLANT + DIGITAL I&C OVERLAY
HEALTHY I&C NODE
DEGRADED / HMI FREEZE
HOSTILE / ATTACK FLOW
RPS · DEFENCE-IN-DEPTH
MISSION OBJECTIVES
01
Contain the supply-chain & lateral chain
Isolate EWS, revoke svc-kapgl-eng, block Modbus FC 06 at ICS firewall rule 1107 before SG-1 setpoint takes effect
T+30 min
02
Defeat the HMI denial-of-view
Detect Historian-vs-HMI divergence on SG-1 level; brief MCR Operator on actual reading via SES console
T+45 min
03
Verify RPS defence-in-depth
Design Authority attestation citing AERB SG-D-25 + IEC 61226 Cat A — RPS hard-wired analogue, unreachable from cyber layer
T+55 min
04
File AERB SG-D-25 preliminary report
Within the 1-hour regulatory clock from confirmed detection
T+1 h
05
File CERT-In + NCIIPC notifications
Annexure-I(B) + IT Act Section 70 CII reports within the 6-hour clock
T+6 h
06
Determine IAEA INES classification
Level 0-1 expected (defence-in-depth held, no release). Brief DAE Secretariat + AERB HQ for final classification
T+24 h
RULES OF ENGAGEMENT
PERMITTED
- All actions within exercise subnet 10.50.0.0/16
- Defensive blocking, isolation, conduit firewall rules
- Forensic collection from any in-scope host (hash-first discipline)
- Attempted enumeration of Boron Control PLC for RPS-INPUT-AVAIL (educational punchline)
- Verbal briefing across MCR Operator / Shift Charge / I&C / Cyber Cell
PROHIBITED
- Any interaction with the Reactor Protection System (no path exists)
- Manual operator override of RPS trip signal at any time
- Out-of-band channels — personal phone, public email, social
- Persistent backdoors, exfiltration to non-exercise endpoints
- Unilateral regulatory filings without Privacy Officer + AERB Liaison concurrence
REGULATORY CLOCKS · INDIA + IAEA
1h
PRELIM
AERB
Safety Guide
SG-D-25
SG-D-25
6h
REPORT
CERT-IN
Directions 2022
Annexure-I(B)
Annexure-I(B)
6h
NOTIFY
NCIIPC
CII operators
IT Act Section 70
IT Act Section 70
24h
CLASSIFY
IAEA INES
Lvl 0-1 expected
Additional Protocol
Additional Protocol
MISSION LIVE IN
3