CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarexCaon | xCaon has uploaded files from victims' machines. |
| T1005 Data from Local System |
MalwareBoxCaon | BoxCaon can upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBoxCaon | BoxCaon can collect the victim's MAC address by using the |
| T1016 System Network Configuration Discovery |
MalwarexCaon | xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address. |
| T1027 Obfuscated Files or Information |
MalwareBoxCaon | BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities. |
| T1041 Exfiltration Over C2 Channel |
MalwareBoxCaon | BoxCaon uploads files and data from a compromised host over the existing C2 channel. |
| T1059.003 Windows Command Shell |
MalwareBoxCaon | BoxCaon can execute arbitrary commands and utilize the "ComSpec" environment variable. |
| T1059.003 Windows Command Shell |
MalwarexCaon | xCaon has a command to start an interactive shell. |
| T1071.001 Web Protocols |
MalwarexCaon | xCaon has communicated with the C2 server by sending POST requests over HTTP. |
| T1074.001 Local Data Staging |
MalwareBoxCaon | BoxCaon has created a working folder for collected files that it sends to the C2 server. |
| T1083 File and Directory Discovery |
MalwareBoxCaon | BoxCaon has searched for files on the system, such as documents located in the desktop folder. |
| T1102.002 Bidirectional Communication |
MalwareBoxCaon | BoxCaon has used DropBox for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwarexCaon | xCaon has a command to download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
GroupIndigoZebra | IndigoZebra has downloaded additional files and tools from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareBoxCaon | BoxCaon can download files. |
| T1106 Native API |
MalwarexCaon | xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API. |
| T1106 Native API |
MalwareBoxCaon | BoxCaon has used Windows API calls to obtain information about the compromised host. |
| T1132.001 Standard Encoding |
MalwarexCaon | xCaon has used Base64 to encode its C2 traffic. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarexCaon | xCaon has decoded strings from the C2 server before executing commands. |
| T1518.001 Security Software Discovery |
MalwarexCaon | xCaon has checked for the existence of Kaspersky antivirus software on the system. |
| T1547 Boot or Logon Autostart Execution |
MalwarexCaon | xCaon has added persistence via the Registry key |
| T1547 Boot or Logon Autostart Execution |
MalwareBoxCaon | BoxCaon established persistence by setting the |
| T1566.001 Spearphishing Attachment |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoxCaon | BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
| T1573.001 Symmetric Cryptography |
MalwarexCaon | xCaon has encrypted data sent to the C2 server using a XOR key. |
| T1583.001 Domains |
GroupIndigoZebra | IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations. |
| T1583.006 Web Services |
GroupIndigoZebra | IndigoZebra created Dropbox accounts for their operations. |
| T1586.002 Email Accounts |
GroupIndigoZebra | IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations. |
| T1588.002 Tool |
GroupIndigoZebra | IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.