ATT&CKGroupsIndigoZebra

IndigoZebra

G0136

Threat group.View on attack.mitre.org

About this group

IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1105
Ingress Tool Transfer

IndigoZebra has downloaded additional files and tools from its C2 server.

T1204.002
Malicious File

IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack.

T1566.001
Spearphishing Attachment

IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments.

T1583.001
Domains

IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations.

T1583.006
Web Services

IndigoZebra created Dropbox accounts for their operations.

T1586.002
Email Accounts

IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.

T1588.002
Tool

IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.

Software3

Campaigns0

None recorded.

References3

  1. Checkpoint IndigoZebra July 2021 Open source
    CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.
  2. HackerNews IndigoZebra July 2021 Open source
    Lakshmanan, R.. (2021, July 1). IndigoZebra APT Hacking Campaign Targets the Afghan Government. Retrieved September 24, 2021.
  3. Securelist APT Trends Q2 2017 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.