Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-02 11:15:15 UTC Home > List all groups > List all tools > List all groups using tool RomeoEcho Tool: RomeoEcho Names RomeoEcho Category Malware Type Backdoor, Info stealer, Exfiltration Description (Novetta) A stark departure from the design pattern found in Romeo-CoreOne-base families, RomeoEcho is a RAT that uses a more interactive command shell format for command identification. With the communications key established and the handshake complete, RomeoEcho’s core activates the communications loop function. RomeoEcho is single-threaded and does not spawn a new thread for incoming connections. As a result, only one client can access a RomeoEcho-infected node at a time. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool RomeoEcho Changed Name Country Observed APT groups   Lazarus Group, Hidden Cobra, Labyrinth Chollima 2007-May 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bdfc3b30-4472-4f49-910b-cad0effb50f8 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bdfc3b30-4472-4f49-910b-cad0effb50f8 Page 1 of 1