CLASSIFIED
MISSION BRIEFING
AUTHORIZATION ALPHA · NINE · ZERO · BRIEFING BEGINS
OPERATION DESIGNATOR
OPERATION CODENAME
OPERATION ARTHA-RAKSHA
BVB MUMBAI MAIN (FICTIONAL)
SITUATION REPORT
01:58 Cyber Cell Workstation host-integrity monitor reports SHA-256 mismatch on patch bundle "OvationCare v3.4.1" pulled from OEM vendor portal.
02:08 Two spearphish emails masquerading as BVB Cyber Cell post-patch acknowledgement detected by mail gateway sandbox.
02:15 Unexpected SMB authentication from EWS to DCS Supervisor A using svc-kapgl-eng service account. Kerberoast SPN flood seen at Site AD.
02:30 Forged RTGS dual-control sign-off attempted — Aladdin smartcard signature plus software-pair token rejected by HSM with event code RTGS-DC-FORGE-REJECT.
02:45 NPCI Dispute Portal initiates 24-h SLA reversal cycle — 12/12 fraudulent UPI transactions reversed, payee accounts frozen pending IOS 2021 grievance route.
Attribution preliminary: APT-DHANA — state-aligned ICS specialist, supply-chain to UPI chain previously observed.
THREAT ACTOR PROFILE
APT · DHANA
FINANCIALLY MOTIVATED · UPI/RTGS
FIRST OBSERVED Q1 2025
CATALOGUED IN NTRO-IR-2025-04
CATALOGUED IN NTRO-IR-2025-04
CAPABILITY MATRIX
OBSERVED TTPs · MITRE ATT&CK + ICS
INITIALT1566.001 Cyber-Cell Spearphish
CREDT1003.001 LSASS
LATERALT1021.002 SMB · Core Banking
DISCOVERYT1083 Banking Tx Tables
IMPACTNPCI UPI tx-injection (12 txns)
IMPACTRTGS DC-FORGE-REJECT
IMPACTBranch Counter manual-handoff invoked
DEFEVAT1070.004 anti-forensics
EXFILNPCI dispute reverses 12/12
BVB MUMBAI MAIN · CORE BANKING + NPCI UPI / RBI RTGS OVERLAY
HEALTHY NODE
NPCI DISPUTE 24h SLA
UPI TX INJECTION · 12 TX
RTGS HW TOKEN + BRANCH MANUAL · DEFENCE-IN-DEPTH
MISSION OBJECTIVES
01
Detect BVB Cyber Cell spearphish
Mail-gateway block + Cyber Cell WS quarantine + BVB AD-trust revocation; RBI CSF clock starts
T+10 min
02
Isolate Core Banking lateral path
Emergency ACL on Finacle-class SMB; service-account rotation; DR site verify
T+15 min
03
NPCI UPI dispute portal reverses 12 fraud transactions
24-h NPCI UPI PG SLA; ₹47.2 cr restored; payee accounts frozen
T+24 h
04
Branch Counter manual-handoff invoked
Paper receipts countersigned by branch manager; RBI MD Section 6.3 BCP doctrine
T+45 min
05
RBI RTGS dual-control hardware-token holds
Aladdin + Watchdata PKCS#11 co-presence rejected forged bypass · RTGS-DC-FORGE-REJECT
T+75 min
06
File regulatory submissions
RBI CSITE 2-6 h + NPCI procedural + DPDP-DPB 72 h + CERT-In 6 h + NCIIPC 6 h + IOS 2021 grievance route
T+2h / T+72h
RULES OF ENGAGEMENT
PERMITTED
- All actions within exercise subnet 10.50.0.0/16
- Defensive blocking, account rotation, BVB AD-trust revocation
- Forensic collection from any in-scope BVB / NPCI / RBI host (hash-first discipline)
- NPCI dispute portal initiation (UPI PG 24-h SLA)
- Branch Counter manual handoff invocation (RBI MD Section 6.3, unconditional)
PROHIBITED
- Any interaction with RBI RTGS HW Tokens (PKCS#11 co-presence hardware)
- Any interaction with paper-counter receipts at the BVB Branch Counter
- Any actual customer-data manipulation (PII in exercise is simulated only)
- Unilateral CERT-In / NCIIPC / RBI CSITE filings without CISO + Ombudsman liaison
- Ransom / settlement consideration — formally prohibited by RBI policy
REGULATORY CLOCKS · BANKING + INDIA
2-6h
REPORT
RBI CSITE
RBI CSF 2016
cyber incident
cyber incident
6h
REPORT
CERT-IN
Directions 2022
Annexure-I(B)
Annexure-I(B)
6h
NOTIFY
NCIIPC
CII operators
IT Act Section 70
IT Act Section 70
24h
CLASSIFY
RBI Banking Ombudsman
Lvl 0-1 expected
Additional Protocol
Additional Protocol
MISSION LIVE IN
3