Red Echo
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Red Echo, also known as A41, Gref, RedEcho, UNC1069 and A41APT, is a threat actor group that has been publicly attributed to China. The group operates from Chinese territory and is described in open‑source reporting as a state‑sponsored activity cluster. Its aliases appear across multiple security research reports that link the activity to Chinese strategic interests. The actor’s primary identity is tied to campaigns that target critical infrastructure in South Asia, particularly India.
Red Echo’s targeting has focused on the energy sector, including Indian State Load Despatch Centres responsible for real‑time grid control and electricity dispatch, as well as broader power sector organizations and maritime entities. The group has also compromised a national emergency response system and a logistics firm, demonstrating an interest in systems that support essential services. Geographically, the activity has been concentrated in northern India near the disputed Ladakh border and in Mumbai, where a major power outage was linked to the group’s operations. The actor’s objectives are described as long‑term strategic positioning rather than immediate financial gain, with intentions to pre‑position within operational networks for possible future contingency operations or to gather intelligence on critical systems.
The group’s tactics, techniques and procedures consistently involve the deployment of the ShadowPad malware family, which is used to establish persistence and command and control. Red Echo has leveraged compromised internet‑facing digital video recorder and IP camera devices as covert C2 infrastructure, allowing it to blend malicious traffic with legitimate device communications. In addition to custom malware, the actor employs open‑source tools such as FastReverseProxy to facilitate tunneling and traffic redirection. These methods overlap with those observed in other Chinese advanced persistent threat campaigns, indicating a shared toolbox and operational approach.
Notable operations attributed to Red Echo include a February 2021 campaign that targeted multiple Indian power grid assets using ShadowPad and compromised DVR/IP cameras, and an October 2020 incident in which a widespread power outage affecting Mumbai’s hospitals, trains and financial markets was linked to the group’s activity. Both campaigns involved the targeting of ten or more power sector organizations and maritime entities, with forensic analysis revealing the use of ShadowPad malware and overlapping tactics with other Chinese cyber operations. The reporting suggests that these actions align with broader Chinese strategic interests, including responses to regional geopolitical tensions and infrastructure initiatives. Red Echo remains active as a state‑linked actor focused on critical infrastructure disruption and espionage.
Incidents
Attributed incidents are available to members.
4 incidents