RedEcho

MITRE ATT&CK: G1042 View on attack.mitre.org

Aliases: RedEcho

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:59:43

Targeted industries: energy-and-utilities government-and-public-sector transportation-and-logistics

Targeted regions: country_code:in

Context

RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.

Detection coverage

  • 2 YARA rules
  • 37 Sigma rules

Malware & tools used

  • Dynamic Resolution (attack-pattern)
  • Web Protocols (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Domains (attack-pattern)
  • ShadowPad (malware)

Reports & references

  • recordedfuture.com — Redecho Targeting Indian Power Sector (report)
  • therecord.media — Redecho Group Parks Domains After Public Exposure (report)
  • MITRE ATT&CK — G1042 (report)
  • go.recordedfuture.com — Cta 2021 0228 (report)
  • go.recordedfuture.com — Ta 2022 0406 (report)

Attributed from

  • Indian Critical Infrastructure Intrusions (campaign)

External references