Thanks
@airforce. BSNL's public IP ranges are public information, probably when the attackers noticed increased success rate for BSNL IP ranges, they may have targetted BSNL IP ranges more extensively.
Also, once you insert a malicious
DNS resolver, they can potentially hijack your traffic elsewhere for non HTTPS traffic.
I'm still curious to know, how the attack itself worked, and what kind of workload the affected PC's or networks were being made to do.