xCaon is a previously undocumented Windows backdoor associated with the suspected Chinese-speaking espionage cluster IndigoZebra. Samples have been observed dating back to at least 2014, and the malware has been linked to campaigns targeting political and government-related entities, including activity in Kyrgyzstan and Uzbekistan. It has also been connected by similarity to the later BoxCaon tooling used in intrusions against Afghan government targets.
xCaon supports command-and-control over HTTP and uses multiple layers of traffic obfuscation, including Base64 encoding and XOR encryption, with strings and server-supplied commands decoded before execution. On compromised hosts it performs local reconnaissance by querying network adapter information and collecting the victim system’s MAC address through native Windows API calls. It also performs security software discovery, including checks for the presence of Kaspersky antivirus, indicating basic defensive-awareness and evasion behavior.
Operationally, xCaon functions as a remote access backdoor capable of receiving commands from its operators and uploading files from victim machines, making it suitable for espionage-oriented post-compromise collection and exfiltration. Its observed tradecraft and targeting align with long-running state-linked intelligence collection operations focused on governmental and political organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses GetAdaptersInfo to retrieve victim MAC addresses.
Backdoor that uses GetAdaptersInfo to obtain the victim's MAC address.
Backdoor that encrypts data sent to its C2 server using XOR.
Malware that uploads files from victim machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.