Threat actor
Aarogya Setu
Last fetched
Aarogya Setu is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Aarogya Setu is a mobile application developed by the Government of India in April 2020 to perform COVID-19 contact tracing. It pairs Bluetooth handshakes with periodic GPS pings to flag when users have been near someone who later tests positive, then offers risk scores and health guidance. Since the pandemic, the platform has been folded into the National Health App stack, adding vaccination certificates and other digital health services. The app embeds far-reaching surveillance capabilities. On sign-up, it demands granular personal data, such as name, phone number, age, sex, profession, travel and even smoking history, which are transmitted to a central government server. Continuous collection of live location and proximity logs lets authorities recreate a user’s movements and social graph, described by critics as a sophisticated surveillance system.
Techniques by tactic
No ATT&CK techniques are recorded for Aarogya Setu in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Aarogya Setu today — this states the absence of a published link, not that Aarogya Setu has no infrastructure.
References
- https://www.india.com/news/india/sophisticated-surveillance-system-rahul-gandhi-raises-concerns-over-aarogya-setu-app-4017747/
- https://techcrunch.com/2020/05/05/aarogya-setu-app-security-privacy-concerns-india-response/
- https://www.cbsnews.com/news/coronavirus-india-contact-tracing-app-privacy-data-security-concerns-aarogya-setu-forced-on-millions/
- https://www.theguardian.com/world/2020/may/04/how-safe-is-it-really-privacy-fears-over-india-coronavirus-app
- https://www.codastory.com/surveillance-and-control/india-coronavirus-surveillance/
- https://www.livemint.com/industry/infotech/why-privacy-advocates-have-concerns-over-aarogya-setu-app-11588509094177.html
- https://www.rfi.fr/en/international/20200508-compulsory-phone-app-raises-fears-of-india-s-flight-towards-super-surveillance-state
- https://scroll.in/article/961641/no-covid-19-silver-bullet-aarogya-setu-endangers-indias-privacy-and-its-usefulness-is-uncertain
- https://www.cnbctv18.com/technology/xiaomi-will-pre-install-aarogya-setu-app-on-new-devices-if-govt-orders-says-manu-jain-5843991.htm
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Aarogya Setu into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.