Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupRedEcho | RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports. |
| T1568 Dynamic Resolution |
GroupRedEcho | RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1568 Dynamic Resolution |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1571 Non-Standard Port |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
GroupRedEcho | RedEcho has used non-standard ports such as TCP 8080 for HTTP communication. |
| T1573.002 Asymmetric Cryptography |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
GroupRedEcho | RedEcho uses SSL for network communication. |
| T1583.001 Domains |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
GroupRedEcho | RedEcho has registered domains spoofing Indian critical infrastructure entities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.