BoxCaon is a Windows backdoor associated with the suspected Chinese-speaking espionage actor IndigoZebra and linked by tradecraft and code lineage to the xCaon malware family. It has been used in targeted intrusions against Afghan government entities, including senior officials, as part of espionage operations that also align with earlier IndigoZebra activity against political organizations in Central Asia.
BoxCaon is designed for remote command execution, host profiling, file collection, and data exfiltration. It gathers information from compromised systems using Windows API calls, including collection of network adapter details such as the victim’s MAC address. It can create a local working directory to stage collected material, download files or enumerate folder contents on the victim system, and upload stolen files and command results from the compromised host.
A defining characteristic of BoxCaon is its abuse of Dropbox for command-and-control and exfiltration. The malware creates victim-specific folders in an attacker-controlled Dropbox account, retrieves operator tasking from that cloud-hosted structure, and sends back collected data over the same command channel. This use of a legitimate cloud service helps blend malicious traffic with normal enterprise activity and supports covert long-term espionage.
Observed delivery involved targeted spearphishing using high-trust government-themed lures and password-protected archive attachments that initiated installation of the backdoor. The malware’s functionality and operational use indicate a purpose-built espionage implant focused on persistent remote access and theft of confidential information from Windows systems in government and political environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The backdoor, dubbed 'BoxCaon,' is capable of stealing confidential data stored on the device, running arbitrary commands, and exfiltrating the results back to the Dropbox folder."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
ADVSTORESHELL exfiltrates data over the same channel used for C2.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collects victim MAC addresses using the GetAdaptersInfo API.
Enterprise New Software: ... BoxCaon ... xCaon
Malware capable of uploading files from compromised hosts.
Backdoor that uses GetAdaptersInfo to collect the victim's MAC address.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.