ATT&CKReferencesCheckpoint IndigoZebra July 2021

Checkpoint IndigoZebra July 2021

CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarexCaon

xCaon has uploaded files from victims' machines.

T1005
Data from Local System
MalwareBoxCaon

BoxCaon can upload files from a compromised host.

T1016
System Network Configuration Discovery
MalwareBoxCaon

BoxCaon can collect the victim's MAC address by using the GetAdaptersInfo API.

T1016
System Network Configuration Discovery
MalwarexCaon

xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address.

T1027
Obfuscated Files or Information
MalwareBoxCaon

BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities.

T1041
Exfiltration Over C2 Channel
MalwareBoxCaon

BoxCaon uploads files and data from a compromised host over the existing C2 channel.

T1059.003
Windows Command Shell
MalwareBoxCaon

BoxCaon can execute arbitrary commands and utilize the "ComSpec" environment variable.

T1059.003
Windows Command Shell
MalwarexCaon

xCaon has a command to start an interactive shell.

T1071.001
Web Protocols
MalwarexCaon

xCaon has communicated with the C2 server by sending POST requests over HTTP.

T1074.001
Local Data Staging
MalwareBoxCaon

BoxCaon has created a working folder for collected files that it sends to the C2 server.

T1083
File and Directory Discovery
MalwareBoxCaon

BoxCaon has searched for files on the system, such as documents located in the desktop folder.

T1102.002
Bidirectional Communication
MalwareBoxCaon

BoxCaon has used DropBox for C2 communications.

T1105
Ingress Tool Transfer
MalwarexCaon

xCaon has a command to download files to the victim's machine.

T1105
Ingress Tool Transfer
GroupIndigoZebra

IndigoZebra has downloaded additional files and tools from its C2 server.

T1105
Ingress Tool Transfer
MalwareBoxCaon

BoxCaon can download files.

T1106
Native API
MalwarexCaon

xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API.

T1106
Native API
MalwareBoxCaon

BoxCaon has used Windows API calls to obtain information about the compromised host.

T1132.001
Standard Encoding
MalwarexCaon

xCaon has used Base64 to encode its C2 traffic.

T1140
Deobfuscate/Decode Files or Information
MalwarexCaon

xCaon has decoded strings from the C2 server before executing commands.

T1518.001
Security Software Discovery
MalwarexCaon

xCaon has checked for the existence of Kaspersky antivirus software on the system.

T1547
Boot or Logon Autostart Execution
MalwarexCaon

xCaon has added persistence via the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load which causes the malware to run each time any user logs in.

T1547
Boot or Logon Autostart Execution
MalwareBoxCaon

BoxCaon established persistence by setting the HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load registry key to point to its executable.

T1566.001
Spearphishing Attachment
GroupIndigoZebra

IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments.

T1567.002
Exfiltration to Cloud Storage
MalwareBoxCaon

BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive.

T1573.001
Symmetric Cryptography
MalwarexCaon

xCaon has encrypted data sent to the C2 server using a XOR key.

T1583.001
Domains
GroupIndigoZebra

IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations.

T1583.006
Web Services
GroupIndigoZebra

IndigoZebra created Dropbox accounts for their operations.

T1586.002
Email Accounts
GroupIndigoZebra

IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.

T1588.002
Tool
GroupIndigoZebra

IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.