Malware
xCaon
S0653 · Windows
xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014. xCaon has been used to target political entities in Central Asia, including Kyrgyzstan and Uzbekistan.
ATT&CK S0653
Malware family
Sigma rules0
YARA rules0
Live IOCs0
▤
Techniques Used
11ATT&CK techniques this malware is documented performing. Each links to its detections - Sigma, vendor SIEM rules, and analytics - so you catch the behaviour even when the binary changes.
⚊
Live Indicators
Indicators are defanged for safe handling. Newest first.
Aliases
xCaon
External lookups - second-class, for what we don’t hold ourselves