xCaon is a previously undocumented malware family associated with the IndigoZebra espionage activity. Kaspersky’s 2017 reporting linked IndigoZebra to operations targeting former Soviet republics, and Check Point later identified about 30 xCaon samples, with the earliest dating to 2014. Based on Check Point telemetry, xCaon HTTP variants primarily targeted political entities in Kyrgyzstan and Uzbekistan, and the broader IndigoZebra activity was attributed to a suspected Chinese-speaking threat actor.
High-confidence behaviors described in the source material include command-and-control over HTTP, Base64-encoded C2 traffic, XOR encryption of data sent to the C2 server, and file upload/exfiltration from victim machines. xCaon also performs host reconnaissance and defensive discovery, including checking for the presence of Kaspersky antivirus software and retrieving network adapter information via the Windows GetAdapterInfo() API. The reporting explicitly notes that xCaon uploaded files from victims’ machines.
xCaon is also relevant as the malware family to which Check Point compared BoxCaon, a later Dropbox-based backdoor used in intrusions against the Afghan government and National Security Council. Check Point linked BoxCaon to IndigoZebra based on similarities with xCaon, indicating continuity in tooling and tradecraft across the actor’s campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family linked to IndigoZebra; samples dating back to 2014 are described as HTTP-based C2 variants, used in espionage targeting political entities in Central Asia.
Malware that uses Base64 to encode command-and-control traffic.
Malware that uses Base64 to encode command-and-control traffic.
Malware that checks for Kaspersky antivirus software on the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.