xCaon

S0653

Malware.View on attack.mitre.org

About this malware

xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1005
Data from Local System

xCaon has uploaded files from victims' machines.

T1016
System Network Configuration Discovery

xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address.

T1059.003
Windows Command Shell

xCaon has a command to start an interactive shell.

T1071.001
Web Protocols

xCaon has communicated with the C2 server by sending POST requests over HTTP.

T1105
Ingress Tool Transfer

xCaon has a command to download files to the victim's machine.

T1106
Native API

xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API.

T1132.001
Standard Encoding

xCaon has used Base64 to encode its C2 traffic.

T1140
Deobfuscate/Decode Files or Information

xCaon has decoded strings from the C2 server before executing commands.

T1518.001
Security Software Discovery

xCaon has checked for the existence of Kaspersky antivirus software on the system.

T1547
Boot or Logon Autostart Execution

xCaon has added persistence via the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load which causes the malware to run each time any user logs in.

T1573.001
Symmetric Cryptography

xCaon has encrypted data sent to the C2 server using a XOR key.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Checkpoint IndigoZebra July 2021 Open source
    CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.
  2. Securelist APT Trends Q2 2017 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.