The virus prowling in the domestic arena, authorities said, attacks the openSSL of an online system which is the most essential protocol which encrypts information and data transfer over the Internet.
The Computer Emergency Response Team of India (CERT-In), the nodal agency to combat hacking, phishing and to fortify security-related defences of the country's Internet domain, fears it could compromise personal data and passwords of a user.
"A remote attacker could exploit this vulnerability by submitting crafted TLS or DTLS heartbeat packets to an affected device to retrieve sensitive information, such as private keys, user name and passwords or contents of encrypted traffic from process memory. By leveraging this information, an attacker may be able to decrypt, spoof, or perform man-in-the-middle attacks," the CERT-In said in its latest advisory to Internet users in the country.
More From This Section
The virus, with derives its name from a 'bleeding red heart' motif, has made a number of countries sit up and take notice of its destructive and threatening activities over the last few days.
Two days back, Canada's tax agency had said that it has temporarily cut off public access to its electronic filling services just three weeks before the tax deadline because of security concerns over the "Heartbleed bug."
"It has been confirmed that the virus is active in the Indian cyberspace too. Some of its suspect messages also resemble a 'red-coloured X' motif similar to the red bleeding heart," a cyber security expert told PTI.