IndigoZebra

MITRE ATT&CK: G0136 View on attack.mitre.org

Aliases: IndigoZebra

First seen
2014-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:06:07

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:kz country_code:kg country_code:uz

Context

IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.

Detection coverage

  • 3 YARA rules
  • 125 Sigma rules

Malware & tools used

  • Domains (attack-pattern)
  • Tool (attack-pattern)
  • Web Services (attack-pattern)
  • Email Accounts (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • xCaon (malware)
  • BoxCaon (malware)
  • PoisonIvy (malware)

Reports & references

  • research.checkpoint.com — Indigozebra Apt Continues To Attack Central Asia With Evolving Tools (report)
  • rewterz.com — Rewterz Threat Intel Indigozebra Apt Group Targeting Central Asia Active Iocs (report)
  • Kaspersky — 79332 (report)
  • MITRE ATT&CK — G0136 (report)
  • thehackernews.com — Indigozebra Apt Hacking Campaign (report)

External references