xCaon

MITRE ATT&CK: S0653 View on attack.mitre.org

Aliases: xCaon

First seen
2014-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:07:01

Targeted industries: government-and-public-sector

Targeted regions: country_code:kg country_code:uz

Context

xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.

Detection coverage

  • 1 YARA rules
  • 192 Sigma rules

Malware & tools used

  • Data from Local System (attack-pattern)
  • Web Protocols (attack-pattern)
  • Boot or Logon Autostart Execution (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Native API (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_Mal_Xcaon_Jul_2021_1 (yara-rule)

Reports & references

  • research.checkpoint.com — Indigozebra Apt Continues To Attack Central Asia With Evolving Tools (report)
  • Kaspersky — 79332 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xcaon (report)
  • MITRE ATT&CK — S0653 (report)

External references