Red Echo

Threat Actor updated 4 months ago (2024-05-04T20:17:20.881Z)
Download STIX
Preview STIX
Red Echo, also known as Redfly, is a subgroup within the larger threat actor group Winnti. This group has been identified as responsible for a series of cyber-attacks with malicious intent, targeting various entities globally. In a recent campaign, Red Echo managed to infiltrate and occupy the network of an Asian national electricity provider for six months. During this period, they deployed a Trojan called "ShadowPad" to harvest credentials and gain access to privileged information. This sophisticated attack demonstrated their ability to maintain persistent access within a critical infrastructure network. Researchers from Symantec have tracked multiple subgroups within Winnti, including Blackfly, Greyfly, and in this case, Redfly or Red Echo. These groups are known for their relentless pursuit of intellectual property and sensitive data, often targeting specific sectors. The identification of these subgroups helps cybersecurity professionals better understand the threat landscape and develop more effective defenses against these advanced persistent threats. In another significant incident, Red Echo inserted malicious code into a download link on the webpage for Myanmar's president. This action further underscores the group's capabilities and willingness to target high-profile individuals and institutions. The insertion of malicious code into legitimate websites is a common tactic used by such groups to compromise systems and steal valuable information. These incidents highlight the ongoing threat posed by Red Echo and similar groups, emphasizing the need for robust cybersecurity measures across all sectors.
Description last updated: 2023-11-21T19:24:40.843Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Red Echo Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
10 months ago
Connect the Dots on State-Sponsored Cyber Incidents - Targeting of Myanmar's presidential website
CERT-EU
a year ago
Connect the Dots on State-Sponsored Cyber Incidents - Targeting of Myanmar's presidential website
DARKReading
a year ago
China's Winnti APT Compromises National Grid in Asia for 6 Months