IndigoZebra is a Chinese state-sponsored threat actor targeting former Soviet republics since 2017.
Analyst brief
IndigoZebra is a Chinese state-sponsored threat actor first disclosed in 2017, primarily targeting former Soviet Republics. It gains initial access via Spearphishing Attachments, leading to execution of Malicious Files, and uses xCaon, BoxCaon, and PoisonIvy malware for its operations. The actor engages in resource development by acquiring Domains and Tools to support its intrusions, and establishes C2 channels using Ingress Tool Transfer. Defenders should prioritize detecting targeted phishing emails with malicious attachments, monitoring for newly registered or suspicious domains, and identifying the execution of known malware like PoisonIvy and custom backdoors such as xCaon.
IndigoZebra
unknown
IndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discovery, former Soviet Republics with multiple malware strains including Meterpreter, Poison Ivy, xDown, and a previously unknown backdoor called “xCaon.”