Overview 25 indicators
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
| domain | 25 | G0136-domain.txt |
Techniques 7 ATT&CK
Open in ATT&CK Navigator → or download the layer (7 techniques, layer 4.5)
- T1105 Ingress Tool Transfer
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1583.001 Domains
- T1583.006 Web Services
- T1586.002 Email Accounts
- T1588.002 Tool
Software 3
Principal sources 2 reports
Ranked by how many of this actor's indicators each report brought in.
- 25research.checkpoint.com/2021/indigozebra-apt-continues-to-attac…
- 25otx.alienvault.com/pulse/60ddbf90b3211a60e87da15f
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 25 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
research.checkpoint.com/2021/indigozebra-apt-continues-to-attac… · otx.alienvault.com/pulse/60ddbf90b3211a60e87da15f
2019mfa.com 6z98os.id597.link cdn.muincxoil.com google-upgrade.com help.2019mfa.com hwyigd.laccessal.org ictdp.com id597.link index.google-upgrade.com laccessal.org m.usascd.com mahallafond.com mfa-uz.com mofa.ungov.org muincxoil.com ns01-mfa.ungov.org post.mfa-uz.com tm.2019mfa.com ungov.org update.ictdp.com usascd.com uslugi.mahallafond.com -
research.checkpoint.com/2021/indigozebra-apt-continues-to-attac… · otx.alienvault.com/pulse/60ddbf90b3211a60e87da15f
infodocs.kginfocom.com kginfocom.com ousync.kginfocom.com