NEW: Group Profiler — instant APT intel lookup. Try it →

RedEcho

G1042 China MITRE ATT&CK →

Overview

RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.

Naming & attribution

RedEcho is tracked under 1 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • BITTER — 3 shared techniques (17% overlap)
  • WIRTE — 3 shared techniques (11% overlap)
  • TA2541 — 3 shared techniques (10% overlap)
  • APT42 Iran — 3 shared techniques (9% overlap)
  • APT-C-36 — 3 shared techniques (8% overlap)
  • Gamaredon Group Russia — 4 shared techniques (6% overlap)

TTPs — 5 techniques across 2 tactics

Resource Development

Command and Control

Tools & malware (1)

ShadowPad

Reporting (2)