xCaon
MITRE ATT&CK: S0653 View on attack.mitre.org
Aliases: xCaon
- First seen
- 2014-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:07:01
Targeted industries: government-and-public-sector
Targeted regions: country_code:kg country_code:uz
Context
xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.
Detection coverage
- 1 YARA rules
- 192 Sigma rules
Malware & tools used
- Data from Local System (attack-pattern)
- Web Protocols (attack-pattern)
- Boot or Logon Autostart Execution (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Command Shell (attack-pattern)
- Native API (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- IndigoZebra (threat-actor)
Detection rules
- ARKBIRD_SOLG_Mal_Xcaon_Jul_2021_1 (yara-rule)
Reports & references
- research.checkpoint.com — Indigozebra Apt Continues To Attack Central Asia With Evolving Tools (report)
- Kaspersky — 79332 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xcaon (report)
- MITRE ATT&CK — S0653 (report)