RedEcho is a China-linked threat activity cluster associated with intrusions into Indian critical infrastructure, especially the electric power sector. Public reporting has tied the activity to long-running campaigns against Indian power organizations, including Regional and State Load Dispatch entities responsible for grid balancing and dispatch, as well as additional critical infrastructure such as seaports and an emergency response organization. The activity has been assessed as aligned with Chinese strategic interests during periods of heightened India-China border tensions, with the intrusion pattern more consistent with strategic pre-positioning and intelligence collection against critical infrastructure than with ordinary economic espionage. RedEcho is closely associated with ShadowPad and with infrastructure tracked under AXIOMATICASYMPTOTE. Reporting has identified overlaps in infrastructure, tooling, and tradecraft with other PRC-linked operations, including APT41 and Tonto Team, but available evidence has not conclusively merged RedEcho into an existing public cluster, so it is commonly tracked as a distinct but related activity group. Some reporting also refers to related activity as TAG-38. The group’s known tradecraft includes command-and-control over SSL/TLS and HTTP-based channels, use of spoofed infrastructure themed around Indian critical infrastructure entities, and likely abuse of vulnerable third-party internet-facing devices for command-and-control support. RedEcho has been observed using ShadowPad and the open-source Fast Reverse Proxy tool. Its operations against Indian grid organizations have raised concern because access to dispatch and operational environments could support later disruptive action, even where immediate disruption was not the apparent objective. RedEcho is best understood as a PRC-aligned cyber espionage and pre-positioning actor focused on Indian critical infrastructure, particularly the power sector, with operational characteristics overlapping broader Chinese state-sponsored intrusion ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as prior China-linked activity targeting India’s electricity grid for contextual comparison, not as the main subject of this report.
Referenced as historical context for prior China-linked targeting of India's power sector.
Referenced as a threat actor associated with use of non-standard ports for command-and-control activity.
Listed in annotations as a threat actor associated with the ATT&CK techniques referenced by this Lumma Stealer detection content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.