Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
5
techniques
1
software
10,103
corpus matches
profile
RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.
techniques
5 attributed · most-instrumented first
software
1 malware & tools attributed
ShadowPad
S0596
read this carefully
10,103 corpus matches is not attribution
That count is indicators which exhibit techniques RedEcho is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 10,103