NEW: Group Profiler — instant APT intel lookup. Try it →

IndigoZebra

G0136 China MITRE ATT&CK →

Overview

IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.

Naming & attribution

IndigoZebra is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IndigoZebraLakshmanan, R.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

Capabilities

  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 7 techniques across 4 tactics

Resource Development

Initial Access

Execution

Command and Control

Tools & malware (3)

xCaon · BoxCaon · PoisonIvy

Reporting (3)