Cyberattack
Nuclear Power Plant
Kudankulam NPP — DTrack malware found on administrative network
4 September 2019 (detected); publicly confirmed 30 October 2019
Tamil Nadu, India
Map
8.1690, 77.7120
What happened
India's Nuclear Power Corporation confirmed that malware had infected an internet-connected computer on Kudankulam's administrative network after CERT-In alerted it on 4 September 2019. A Department of Atomic Energy investigation found the affected administrative network was isolated from the plant's critical internal control network; reactor control and safety systems were not affected and generation continued. Independent security researchers identified the malware as DTrack and associated it with the North Korea-linked Lazarus Group, but the Indian government did not formally attribute the intrusion. The record uses the detection date rather than the supplied April–May date, for which no reliable support was found.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Nuclear Power Plant
- Current temperature
- Loading…
- Latitude
- 8.1690°
- Longitude
- 77.7120°
Attribution
Attributed to Lazarus Group (external security-research attribution)
India's official confirmation identified malware on the administrative network but did not attribute the intrusion. Security researchers identified the sample as DTrack, a tool associated with the North Korea-linked Lazarus Group.
