logo

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

ID: 6a466824-42d1-5aff-b3e8-9f339c9e4e9d

STIX ID: report--6a466824-42d1-5aff-b3e8-9f339c9e4e9d

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-23

Author: GReAT

...
...

Kaspersky analyzed a new .NET Native AOT communication module (AzureCommunication.dll) used by the Project CAV3RN espionage framework: it uses Outlook calendar events accessed via Microsoft Graph as a covert C2 channel (with encrypted attachments and a fixed 2050 calendar window), and implements a DNS AAAA-based fallback protocol to recover Microsoft Graph credentials. The module contains hardcoded tenant/client credentials, RSA/AES-GCM crypto for commands and results, a sentinel IPv6 failure address, and numerous IoCs and infrastructure indicators; the authors assess a low-confidence link to OilRig (APT34).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.