Cyberattack

Nuclear Power Plant

Kudankulam NPP — DTrack malware found on administrative network

4 September 2019 (detected); publicly confirmed 30 October 2019

Tamil Nadu, India

8.1690, 77.7120

Loading free detailed map…
No radiological release

What happened

India's Nuclear Power Corporation confirmed that malware had infected an internet-connected computer on Kudankulam's administrative network after CERT-In alerted it on 4 September 2019. A Department of Atomic Energy investigation found the affected administrative network was isolated from the plant's critical internal control network; reactor control and safety systems were not affected and generation continued. Independent security researchers identified the malware as DTrack and associated it with the North Korea-linked Lazarus Group, but the Indian government did not formally attribute the intrusion. The record uses the detection date rather than the supplied April–May date, for which no reliable support was found.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Nuclear Power Plant
Current temperature
Loading…
Latitude
8.1690°
Longitude
77.7120°

Attribution

Attributed to Lazarus Group (external security-research attribution)

India's official confirmation identified malware on the administrative network but did not attribute the intrusion. Security researchers identified the sample as DTrack, a tool associated with the North Korea-linked Lazarus Group.

Sources

  1. Malware infection in Kudankulam Nuclear Power PlantPress Information Bureau, Government of India · Incident reporting
  2. How malware detected at India's nuclear power plant could have been preventedCheck Point Research · DTrack identification and qualified Lazarus attribution