logo

IndigoZebra__2021__IndigoZebra_APT_continues_to_attack_Central_Asia_with_evolving_tools_-_Check_Point_Research.pdf

ID: e1adbd8c-982e-41ca-803b-39f59fda9e25

STIX ID: report--e1adbd8c-982e-41ca-803b-39f59fda9e25

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2021-07-06

Last Modified Date: 2021-07-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research exposes the IndigoZebra APT's long-running cyber-espionage campaign against Central Asian governmental targets (Afghanistan, Kyrgyzstan, Uzbekistan), describing spear-phishing lures, an executable dropper that installs xCaon/BoxCaon backdoors, and a novel BoxCaon variant that uses Dropbox as a C2 channel. The report includes technical analysis (code, persistence, C2 protocol), infrastructure timelines and ASNs, comprehensive IOCs (file hashes, domains, Dropbox account), and MITRE ATT&CK mappings to support detection and mitigation.