DRDO: India is one of the most cyber-attacked nations. Here’s how AI adds another layer to the threat

DRDO: India is one of the most cyber-attacked nations. Here’s how AI adds another layer to the threat

AI’s Rapid Rise Amplifies Cyber Threats, Exposing Global Imbalances and India’s Vulnerabilities

The adoption of artificial intelligence (AI) has outpaced all prior technologies, with ChatGPT reaching a billion users in just three years far faster than the internet’s 15-year timeline. This acceleration has transformed cybersecurity, enabling threats to evolve at unprecedented speed, scale, and sophistication. AI now automates every stage of the cyber kill chain, from reconnaissance to autonomous offensive operations, reshaping the balance of power in cyberspace.

AI-Powered Threats Reshape Cyber Warfare

AI’s impact on cybersecurity is profound, particularly in three key areas:

  1. Automated Reconnaissance & Social Engineering – AI models like ChatGPT mine social media to craft hyper-targeted spear-phishing emails, while deepfakes generate real-time disinformation, eroding trust in digital content.
  2. Polymorphic Malware & Autonomous Attacks – Large language models (LLMs) now generate and adapt malware in real time, evading traditional signature-based defenses. In September 2025, Anthropic reported that a Chinese state-backed group, GTG-1002, used its Claude Code model as an autonomous cyber agent in a multi-stage espionage campaign the first documented case of AI-orchestrated cyber operations.
  3. Zero-Day Vulnerability Discovery – Frontier AI models, such as Anthropic’s Claude Mythos Preview, have autonomously identified thousands of critical zero-day flaws, including a 27-year-old vulnerability in OpenBSD, a security-hardened operating system used in firewalls and critical infrastructure.

These advancements render conventional defenses like static antivirus signatures and delayed patching ineffective against AI-driven threats. Meanwhile, AI also enhances defensive capabilities, enabling real-time threat detection and automated responses, but access to these tools remains concentrated among a few nations.

Geopolitical Imbalances Widen the AI Divide

The global AI ecosystem is dominated by the U.S. and China, which control foundational models, chip design, and data-center infrastructure. This disparity leaves other nations, including India, dependent on foreign technology and vulnerable to AI-enabled cyber threats.

India, the world’s second-most cyber-attacked nation in 2024 (per CloudSEK), faces escalating risks. Recent incidents include:

  • Kudankulam Nuclear Plant Breach – In 2025, the ransomware group World Leaks leaked blueprints and supplier data from India’s largest nuclear facility.
  • Operation Sindoor – Pakistan-backed APT36 targeted India’s defense sector, including the Ministry of Defence, DRDO, and Bharat Operating System Solutions (BOSS) Linux, while disrupting government IT infrastructure like the National Informatics Centre.

Despite these threats, India’s indigenous AI capabilities lag behind, with gaps in foundational models, GPUs, and large-scale data infrastructure.

India’s Response: Policy Shifts and Defensive Measures

Recognizing the urgency, Indian authorities have begun adapting:

  • CERT-In’s AI-Driven Defenses – Since 2025, India’s cybersecurity agency has deployed AI-based threat detection and issued advisories urging organizations to treat vulnerabilities as exploitable within hours, not weeks.
  • Regulatory Frameworks – The Ministry of Electronics and Information Technology is exploring consent-based rules for synthetic content, restrictions on autonomous AI agents, and liability frameworks for AI models.
  • Strategic Adoption – Analysts advocate for "agile adoption" of AI, supply-chain scrutiny, and participation in global tech alliances like Pax Silica to secure India’s digital sovereignty.

As AI and cybersecurity become inseparable, policymakers must integrate them into a unified strategy balancing defense, innovation, and geopolitical resilience. The stakes are clear: nations that fail to adapt risk falling further behind in an AI-driven cyber arms race.

Source: https://indianexpress.com/article/explained/explained-ai/ai-cybersecurity-threats-india-10846344/

Defence Research & Development Organisation (DRDO) cybersecurity rating report: https://www.rankiteo.com/company/defence-research-development-organisation-drdo

"id": "DEF1787574547",
"linkid": "defence-research-development-organisation-drdo",
"type": "Cyber Attack",
"date": "9/2025",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'industry': 'energy',
                        'location': 'India',
                        'name': 'Kudankulam Nuclear Plant',
                        'type': 'critical infrastructure'},
                       {'industry': 'defense',
                        'location': 'India',
                        'name': 'Ministry of Defence',
                        'type': 'government'},
                       {'industry': 'defense research',
                        'location': 'India',
                        'name': 'DRDO',
                        'type': 'government'},
                       {'industry': 'technology',
                        'location': 'India',
                        'name': 'Bharat Operating System Solutions (BOSS) '
                                'Linux',
                        'type': 'government'},
                       {'industry': 'IT infrastructure',
                        'location': 'India',
                        'name': 'National Informatics Centre',
                        'type': 'government'}],
 'attack_vector': ['AI-automated reconnaissance',
                   'spear-phishing',
                   'deepfakes',
                   'polymorphic malware',
                   'zero-day exploits'],
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['nuclear plant blueprints',
                                              'supplier data',
                                              'defense sector documents',
                                              'government IT infrastructure '
                                              'data']},
 'date_publicly_disclosed': '2025-09',
 'description': 'The adoption of artificial intelligence (AI) has accelerated '
                'cyber threats, enabling automated reconnaissance, polymorphic '
                'malware, and zero-day vulnerability discovery. AI-driven '
                'attacks, such as those by Chinese state-backed group GTG-1002 '
                'and Pakistan-backed APT36, have targeted critical '
                'infrastructure in India, including nuclear plants and defense '
                'sectors. India faces escalating risks due to geopolitical '
                'imbalances and dependence on foreign AI technology.',
 'impact': {'data_compromised': ['nuclear plant blueprints',
                                 'supplier data',
                                 'defense sector documents',
                                 'government IT infrastructure data'],
            'operational_impact': ['disruption of government IT infrastructure',
                                   'compromised critical infrastructure'],
            'systems_affected': ['Kudankulam Nuclear Plant',
                                 'Ministry of Defence',
                                 'DRDO',
                                 'Bharat Operating System Solutions (BOSS) '
                                 'Linux',
                                 'National Informatics Centre']},
 'initial_access_broker': {'high_value_targets': ['nuclear plants',
                                                  'defense sector',
                                                  'government IT '
                                                  'infrastructure']},
 'lessons_learned': 'Conventional defenses like static antivirus signatures '
                    'and delayed patching are ineffective against AI-driven '
                    'threats. Nations must adopt agile AI strategies, enhance '
                    'supply-chain scrutiny, and participate in global tech '
                    'alliances to secure digital sovereignty.',
 'motivation': ['espionage',
                'disruption',
                'financial gain',
                'geopolitical advantage'],
 'post_incident_analysis': {'corrective_actions': ['CERT-In’s AI-driven '
                                                   'defenses',
                                                   'regulatory frameworks for '
                                                   'AI',
                                                   'supply-chain scrutiny',
                                                   'participation in global '
                                                   'tech alliances'],
                            'root_causes': ['AI-driven automation of cyber '
                                            'kill chain',
                                            'geopolitical imbalances in AI '
                                            'access',
                                            'dependence on foreign AI '
                                            'technology',
                                            'unpatched vulnerabilities']},
 'ransomware': {'data_exfiltration': True},
 'recommendations': ['Deploy AI-based threat detection and real-time response '
                     'systems',
                     'Treat vulnerabilities as exploitable within hours, not '
                     'weeks',
                     'Implement consent-based rules for synthetic content',
                     'Restrict autonomous AI agents',
                     'Establish liability frameworks for AI models',
                     'Strengthen indigenous AI capabilities in foundational '
                     'models, GPUs, and data infrastructure',
                     'Participate in global tech alliances like Pax Silica'],
 'references': [{'source': 'Anthropic'}, {'source': 'CloudSEK'}],
 'response': {'enhanced_monitoring': 'AI-based threat detection by CERT-In'},
 'threat_actor': ['GTG-1002 (China)',
                  'APT36 (Pakistan)',
                  'World Leaks (ransomware group)'],
 'title': 'AI-Powered Cyber Threats and India’s Vulnerabilities',
 'type': ['espionage', 'ransomware', 'cyber warfare'],
 'vulnerability_exploited': ['27-year-old OpenBSD vulnerability',
                             'unpatched systems']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.