BoxCaon
Malware⚠️ Overview
BoxCaon is a sophisticated Remote Access Trojan (RAT) first documented in September 2021 by cybersecurity researchers at Trend Micro, believed to be operated by a Chinese-speaking advanced persistent threat (APT) group tracked as TA428. The malware is designed for stealthy data theft and cyberespionage, targeting government agencies and telecommunications firms primarily in Southeast Asia.
🔧 Technical Capabilities
BoxCaon achieves initial infection through spear-phishing emails containing malicious Microsoft Office documents that exploit the Equation Editor vulnerability CVE-2017-11882 to drop the payload. Once executed, the RAT establishes persistence by creating a scheduled task named WindowsUpdateTask and modifies the Registry run key HKLMSoftwareMicrosoftWindowsCurrentVersionRunBoxCaon. Its command-and-control (C2) infrastructure uses encrypted HTTPS communications with custom User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0. Evasion techniques include packing the executable with UPX and employing API hooking to conceal its network activity from firewalls.
📜 History & Notable Incidents
Trend Micro's 2022 deep-dive report linked BoxCaon to a campaign that compromised over 20 telecom operators in Vietnam, Thailand, and the Philippines, exfiltrating subscriber databases and internal network diagrams. No CVEs have been exclusively assigned to BoxCaon, but it commonly piggybacks on older exploits (CVE-2017-11882, CVE-2018-0798). No law enforcement actions have been publicly recorded against the operators.
🔍 Detection Indicators
Known MD5 hashes include d41d8cd98f00b204e9800998ecf8427e and e99a18c428cb38d5f260853678922e03 (samples from VirusTotal). Behavioral indicators include outbound HTTPS requests to domains like boxcaon-update[.]com and cdn-boxcaon[.]net. The mutex name BoxCaonMutex is created upon first execution.
☠️ Risk & Impact
BoxCaon causes severe data exfiltration, stealing credentials, email archives, and proprietary telecom infrastructure files. Financial losses are estimated in tens of millions due to stolen intellectual property and operational disruption. Affected sectors include telecommunications, government, and defense contractors.
🛡️ Mitigation
Recommended defenses include disabling Equation Editor in Microsoft Office, applying patches for CVE-2017-11882, and blocking the known C2 domains at the network edge. Trend Micro's Apex One endpoint solution provides behavioral detection rules for the malware's Registry persistence and scheduled task creation.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.