xCaon

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[xCaon](https://attack.mitre.org/software/S0653) is an HTTP variant of the [BoxCaon](https://attack.mitre.org/software/S0651) malware family that has used by [IndigoZebra](https://attack.mitre.org/groups/G0136) since at least 2014. [xCaon](https://attack.mitre.org/software/S0653) has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.(Citation: Checkpoint IndigoZebra July 2021)(Citation: Securelist APT Trends Q2 2017)

Associated Techniques (11)
ID ATT&CK Tactics
T1005 Data from Local System -
T1016 System Network Configuration Discovery -
T1059.003 Windows Command Shell -
T1071.001 Web Protocols -
T1105 Ingress Tool Transfer -
T1106 Native API -
T1132.001 Standard Encoding -
T1140 Deobfuscate/Decode Files or Information -
T1518.001 Security Software Discovery -
T1547 Boot or Logon Autostart Execution -
T1573.001 Symmetric Cryptography -
Used by Actors (1)
Metadata
ID: 87
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00