Malware.View on attack.mitre.org
xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
xCaon has uploaded files from victims' machines. |
| T1016 System Network Configuration Discovery |
xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address. |
| T1059.003 Windows Command Shell |
xCaon has a command to start an interactive shell. |
| T1071.001 Web Protocols |
xCaon has communicated with the C2 server by sending POST requests over HTTP. |
| T1105 Ingress Tool Transfer |
xCaon has a command to download files to the victim's machine. |
| T1106 Native API |
xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API. |
| T1132.001 Standard Encoding |
xCaon has used Base64 to encode its C2 traffic. |
| T1140 Deobfuscate/Decode Files or Information |
xCaon has decoded strings from the C2 server before executing commands. |
| T1518.001 Security Software Discovery |
xCaon has checked for the existence of Kaspersky antivirus software on the system. |
| T1547 Boot or Logon Autostart Execution |
xCaon has added persistence via the Registry key |
| T1573.001 Symmetric Cryptography |
xCaon has encrypted data sent to the C2 server using a XOR key. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.