G0136 IndigoZebra
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.123
Item | Value |
---|---|
ID | G0136 |
Associated Names | |
Version | 1.0 |
Created | 24 September 2021 |
Last Modified | 16 October 2021 |
Navigation Layer | View In ATT&CK® Navigator |
Techniques Used
Domain | ID | Name | Use |
---|---|---|---|
enterprise | T1583 | Acquire Infrastructure | - |
enterprise | T1583.001 | Domains | IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations.2 |
enterprise | T1583.006 | Web Services | IndigoZebra created Dropbox accounts for their operations.12 |
enterprise | T1586 | Compromise Accounts | - |
enterprise | T1586.002 | Email Accounts | IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.2 |
enterprise | T1105 | Ingress Tool Transfer | IndigoZebra has downloaded additional files and tools from its C2 server.2 |
enterprise | T1588 | Obtain Capabilities | - |
enterprise | T1588.002 | Tool | IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.23 |
enterprise | T1566 | Phishing | - |
enterprise | T1566.001 | Spearphishing Attachment | IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments.12 |
enterprise | T1204 | User Execution | - |
enterprise | T1204.002 | Malicious File | IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack.1 |
Software
References
-
Lakshmanan, R.. (2021, July 1). IndigoZebra APT Hacking Campaign Targets the Afghan Government. Retrieved September 24, 2021. ↩↩↩↩
-
CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021. ↩↩↩↩↩↩↩↩↩
-
Kaspersky Lab’s Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018. ↩↩↩