RedEcho
RedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we use to track infrastructure that comprises ShadowPad C2s, which is shared between several Chinese threat activity groups
RedEcho is a Chinese-affiliated threat actor targeting Asia-Pacific telecommunications and government entities using ShadowPad malware.
RedEcho is a threat actor assessed to be Chinese-affiliated, though its precise type remains unknown. It primarily targets telecommunications and government entities in the Asia-Pacific region. The group leverages the ShadowPad malware, using infrastructure tracked as 'AXIOMATICASYMPTOTE' for C2, employing techniques like Web Protocols and Dynamic Resolution. Defenders should scrutinize network traffic for ShadowPad indicators and remain vigilant against suspicious domain registrations.
RedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we use to track infrastructure that comprises ShadowPad C2s, which is shared between several Chinese threat activity groups
Monitoring domain registration and reputation can help detect potential malicious activity.
Monitoring unusual network requests and dynamic DNS resolution can help detect C2 communication.
RedEcho primarily targets telecommunications and government entities in the Asia-Pacific region.
AXIOMATICASYMPTOTE is a term used to track infrastructure that comprises ShadowPad C2s, which is shared between several Chinese threat activity groups.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.