Threat group.View on attack.mitre.org
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
| Technique | Procedure example |
|---|---|
| T1105 Ingress Tool Transfer |
IndigoZebra has downloaded additional files and tools from its C2 server. |
| T1204.002 Malicious File |
IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack. |
| T1566.001 Spearphishing Attachment |
IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments. |
| T1583.001 Domains |
IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations. |
| T1583.006 Web Services |
IndigoZebra created Dropbox accounts for their operations. |
| T1586.002 Email Accounts |
IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations. |
| T1588.002 Tool |
IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.