New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
ID: 6a466824-42d1-5aff-b3e8-9f339c9e4e9d
STIX ID: report--6a466824-42d1-5aff-b3e8-9f339c9e4e9d
Feed Name: Securelist by Kaspersky
Kaspersky analyzed a new .NET Native AOT communication module (AzureCommunication.dll) used by the Project CAV3RN espionage framework: it uses Outlook calendar events accessed via Microsoft Graph as a covert C2 channel (with encrypted attachments and a fixed 2050 calendar window), and implements a DNS AAAA-based fallback protocol to recover Microsoft Graph credentials. The module contains hardcoded tenant/client credentials, RSA/AES-GCM crypto for commands and results, a sentinel IPv6 failure address, and numerous IoCs and infrastructure indicators; the authors assess a low-confidence link to OilRig (APT34).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
