IndigoZebra__2021__IndigoZebra_APT_continues_to_attack_Central_Asia_with_evolving_tools_-_Check_Point_Research.pdf
ID: e1adbd8c-982e-41ca-803b-39f59fda9e25
STIX ID: report--e1adbd8c-982e-41ca-803b-39f59fda9e25
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2021-07-06
Last Modified Date: 2021-07-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research exposes the IndigoZebra APT's long-running cyber-espionage campaign against Central Asian governmental targets (Afghanistan, Kyrgyzstan, Uzbekistan), describing spear-phishing lures, an executable dropper that installs xCaon/BoxCaon backdoors, and a novel BoxCaon variant that uses Dropbox as a C2 channel. The report includes technical analysis (code, persistence, C2 protocol), infrastructure timelines and ASNs, comprehensive IOCs (file hashes, domains, Dropbox account), and MITRE ATT&CK mappings to support detection and mitigation.
