RedEcho
MITRE ATT&CK: G1042 View on attack.mitre.org
Aliases: RedEcho
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:59:43
Targeted industries: energy-and-utilities government-and-public-sector transportation-and-logistics
Targeted regions: country_code:in
Context
RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.
Detection coverage
- 2 YARA rules
- 37 Sigma rules
Malware & tools used
- Dynamic Resolution (attack-pattern)
- Web Protocols (attack-pattern)
- Non-Standard Port (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Domains (attack-pattern)
- ShadowPad (malware)
Reports & references
- recordedfuture.com — Redecho Targeting Indian Power Sector (report)
- therecord.media — Redecho Group Parks Domains After Public Exposure (report)
- MITRE ATT&CK — G1042 (report)
- go.recordedfuture.com — Cta 2021 0228 (report)
- go.recordedfuture.com — Ta 2022 0406 (report)
Attributed from
- Indian Critical Infrastructure Intrusions (campaign)