xCaon — Malware Profile
xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.
MITRE ATT&CK techniques (11)
- T1005 Data from Local System
- T1016 System Network Configuration Discovery
- T1059.003 Windows Command Shell
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1132.001 Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1518.001 Security Software Discovery
- T1547 Boot or Logon Autostart Execution
- T1573.001 Symmetric Cryptography