RedEcho

G1042

Threat group.View on attack.mitre.org

About this group

RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1071.001
Web Protocols

RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports.

T1568
Dynamic Resolution

RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1571
Non-Standard Port

RedEcho has used non-standard ports such as TCP 8080 for HTTP communication.

T1573.002
Asymmetric Cryptography

RedEcho uses SSL for network communication.

T1583.001
Domains

RedEcho has registered domains spoofing Indian critical infrastructure entities.

Software1

Campaigns0

None recorded.

References2

  1. RecordedFuture RedEcho 2021 Open source
    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.
  2. RecordedFuture RedEcho 2022 Open source
    Recorded Future Insikt Group. (2022, April 6). Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group. Retrieved November 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.