IndigoZebra
Overview
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
Naming & attribution
IndigoZebra is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| IndigoZebra | Lakshmanan, R. |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Ferocious Kitten Iran — 4 shared techniques (44% overlap)
- Ajax Security Team Iran — 3 shared techniques (30% overlap)
- BITTER — 5 shared techniques (28% overlap)
- DarkHydrus — 3 shared techniques (27% overlap)
- Nomadic Octopus Russia — 3 shared techniques (27% overlap)
- LazyScripter — 5 shared techniques (23% overlap)
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 7 techniques across 4 tactics
Resource Development
-
T1583.001Domains -
T1583.006Web Services -
T1586.002Email Accounts -
T1588.002Tool
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1204.002Malicious File
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (3)
xCaon · BoxCaon · PoisonIvy
Reporting (3)
- IndigoZebra APT Hacking Campaign Targets the Afghan Government — Lakshmanan, R.
- IndigoZebra APT continues to attack Central Asia with evolving tools — CheckPoint Research
- APT Trends report Q2 2017 — Kaspersky Lab's Global Research & Analysis Team