RedEcho
RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions targeting Indian critical infrastructure entities. Reporting in the provided content links RedEcho to campaigns against India’s critical national infrastructure, including the 2021 targeting of the country’s electricity grid, and notes that Insikt Group identified the group as targeting 10 Indian power generation/transmission organizations and two maritime organizations. The content also states RedEcho overlaps with other PRC-linked threat groups, including APT41, and is linked to ShadowPad malware use through shared infrastructure. Observed tradecraft in the provided content includes registration of domains spoofing Indian critical infrastructure entities; command-and-control/network communication using SSL over TCP 443; HTTP traffic over non-standard ports, including TCP 8080; use of web protocols for command and control; and use of non-standard ports. ATT&CK techniques explicitly referenced in the content for RedEcho are T1071.001 (Web Protocols), T1219 (Remote Access Tools), T1041 (Exfiltration Over C2 Channel), T1573.002 (Asymmetric Cryptography), and T1571 (Non-Standard Port). Known alias in the provided content: redecho.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Utilities
Where they target
Geographies tied to known operations.
- 🇮🇳 India
Tradecraft
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as historical context for prior China-linked targeting of India's power sector.
Referenced as a threat actor associated with use of non-standard ports for command-and-control activity.
Listed in annotations as a threat actor associated with the ATT&CK techniques referenced by this Lumma Stealer detection content.
Listed in the detection annotations as a threat actor associated with the covered techniques.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.