StatsFirst seenMay 2022Last seenSeptember 2026MITRE ATT&CK techniques11 techniques across 6 tactics.TA0002 ExecutionT1059Command and Scripting InterpreterT1059.003Windows Command ShellT1106Native APITA0003 PersistenceT1547Boot or Logon Autostart ExecutionTA0005 StealthT1140Deobfuscate/Decode Files or InformationTA0007 DiscoveryT1016System Network Configuration DiscoveryT1518Software DiscoveryT1518.001Security Software DiscoveryTA0009 CollectionT1005Data from Local SystemTA0011 Command and ControlT1071Application Layer ProtocolT1071.001Web ProtocolsT1105Ingress Tool TransferT1132Data EncodingT1132.001Standard EncodingT1573Encrypted ChannelT1573.001Symmetric CryptographyAssociated groupsG0136IndigoZebraAlert name variantsAlert NameEngineWin32.Trojan.XcaonATP Sandbox Adv. HeuristicsRelated blogsCloud Threats Memo: Preventing the Exploitation of Dropbox as a Command and ControlJuly 8, 2021·1 min readRelated familiesLatrodectusQakBotBazarBisonalCobalt Strike
Cloud Threats Memo: Preventing the Exploitation of Dropbox as a Command and ControlJuly 8, 2021·1 min read