Malware.View on attack.mitre.org
BoxCaon is a Windows backdoor that was used by IndigoZebra in a 2021 spearphishing campaign against Afghan government officials. BoxCaon's name stems from similarities shared with the malware family xCaon.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
BoxCaon can upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
BoxCaon can collect the victim's MAC address by using the |
| T1027 Obfuscated Files or Information |
BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities. |
| T1041 Exfiltration Over C2 Channel |
BoxCaon uploads files and data from a compromised host over the existing C2 channel. |
| T1059.003 Windows Command Shell |
BoxCaon can execute arbitrary commands and utilize the "ComSpec" environment variable. |
| T1074.001 Local Data Staging |
BoxCaon has created a working folder for collected files that it sends to the C2 server. |
| T1083 File and Directory Discovery |
BoxCaon has searched for files on the system, such as documents located in the desktop folder. |
| T1102.002 Bidirectional Communication |
BoxCaon has used DropBox for C2 communications. |
| T1105 Ingress Tool Transfer |
BoxCaon can download files. |
| T1106 Native API |
BoxCaon has used Windows API calls to obtain information about the compromised host. |
| T1547 Boot or Logon Autostart Execution |
BoxCaon established persistence by setting the |
| T1567.002 Exfiltration to Cloud Storage |
BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.