Uptime Hamster: 10d 12h 9mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza IndigoZebra

IndigoZebra

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: APT INDIGOZEBRA
Ver en IntelTracker → APTTrail →
IndigoZebra is a state-sponsored advanced persistent threat group, assessed with high confidence to be of Chinese origin, that has been active since at least 2014. The group is primarily motivated by cyber espionage, specifically targeting governments and political entities in Central Asia, including Kyrgyzstan, Afghanistan, and Uzbekistan. They are distinguished by their consistent targeting of government institutions, use of custom backdoors like xCaon and its variant BoxCaon, and their ability to adapt C2 mechanisms, notably through the abuse of legitimate cloud services like Dropbox. While they have been referred to as a "Chinese-speaking threat actor," no other aliases for IndigoZebra itself are widely known.

Aliases del actor

APT INDIGOZEBRA

Actores similares

apt-indigozebraactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownotx.alienvault.comAPT INDIGOZEBRA indicators and references
Webunknownresearch.checkpoint.comAPT INDIGOZEBRA indicators and references
Repositoriounknowngithub.comAPT INDIGOZEBRA indicators and references
Webunknownraw.githubusercontent.comAPT INDIGOZEBRA indicators and references
Webunknownotx.alienvault.comAPT INDIGOZEBRA indicators and references
Motivacion