RedEcho is a PRC-aligned threat activity group tracked for sustained intrusions against Indian critical infrastructure, primarily the electricity sector, amid heightened India–China border tensions. The activity has targeted Indian power organizations, including Regional and State Load Despatch Centres responsible for grid balancing and electricity dispatch, as well as Indian seaports and an emergency-response entity. Operations from 2020 through at least 2022 were assessed as strategic pre-positioning and intelligence collection that could enable future disruptive action, geopolitical signaling, or influence activity rather than economic espionage. RedEcho used ShadowPad-associated command-and-control infrastructure, encrypted web communications, and Fast Reverse Proxy tooling. Reporting has identified infrastructure and tradecraft overlaps with Chinese state-sponsored activity, including APT41/Barium and Tonto Team, but RedEcho remains tracked as a distinct activity cluster because attribution to a specific established group has not been conclusively demonstrated. The actor is also known as Red Echo.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as prior China-linked activity targeting India’s electricity grid for contextual comparison, not as the main subject of this report.
Referenced as historical context for prior China-linked targeting of India's power sector.
Referenced as a threat actor associated with use of non-standard ports for command-and-control activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.