New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Kaspersky detailed Project CAV3RN, a modular cyberespionage framework targeting Israel that now uses AzureCommunication.dll and Microsoft Graph Outlook calendar events for C2. When Graph authentication fails, the module can recover TenantId, ClientId, ClientSecret, and UserEmail through DNS AAAA queries against cloudlanecdn[.]com, a capability that reinforces the report’s low-confidence attribution to OilRig (APT34). #ProjectCAV3RN #AzureCommunication.dll #cloudlanecdn.com #OilRig #APT34

Keypoints

  • Project CAV3RN is a modular framework used for cyberespionage activity against targets in Israel.
  • In April 2026, the framework shifted from a three-component design to a controller-based architecture with plugins and a dedicated communication component.
  • The newly identified module, AzureCommunication.dll, uses Microsoft Graph and Outlook calendar events as its command-and-control channel.
  • Commands and results are hidden in calendar events scheduled for a fixed one-hour window in 2050, using subjects such as Event ID, Boss update ID, and Boss Report ID.
  • Inbound commands are protected with RSA-OAEP-SHA256 and AES-256-GCM, while outbound results are encrypted and split into attachment chunks before upload.
  • If Microsoft Graph authentication or validation fails, the module can recover configuration values through DNS AAAA responses from cloudlanecdn[.]com.
  • The report says the infrastructure and behavior are consistent with a low-confidence association to OilRig (APT34).

MITRE Techniques

  • [T1071.004] Application Layer Protocol: DNS – Used as a fallback channel to recover Microsoft Graph configuration values through AAAA queries (‘the module attempts to retrieve replacement TenantId, ClientId, ClientSecret, and UserEmail values through actor-controlled AAAA responses’).
  • [T1071.007] Application Layer Protocol: WebSocket – The earlier CAV3RN communication component used WebSocket-enabled C2 before the new module replaced it (‘a dedicated WebSocket-enabled C2 communication component’).
  • [T1071.001] Application Layer Protocol: Web Protocols – The previous communication module retrieved commands and sent results over HTTP/WebSocket, and the new module uses Microsoft Graph HTTPS requests (‘retrieved commands and transmitted execution results over HTTP/WebSocket’).
  • [T1105] Ingress Tool Transfer – The module downloads command attachments from Outlook calendar events before deleting the event (‘downloads its attachments, and deletes it after consumption’).
  • [T1027] Obfuscated Files or Information – AzureCommunication.dll is compiled with .NET Native AOT to hinder analysis by removing metadata and intermediate language (‘turns the managed application into native machine code and removes most of the metadata’).
  • [T1132.001] Data Encoding: Standard Encoding – The agent ID is converted into uppercase hexadecimal before being embedded in DNS queries (‘converts its UTF-8 bytes into two-character uppercase hexadecimal values’).
  • [T1048] Exfiltration Over Alternative Protocol – Results are encrypted and uploaded through Microsoft Graph calendar event attachments instead of conventional exfiltration paths (‘creates an event, uploads encrypted result attachments’).
  • [T1567.002] Exfiltration to Cloud Storage – The framework uses Microsoft-hosted cloud services for command and result exchange via Microsoft Graph and Outlook calendar objects (‘uses Microsoft Graph to access Outlook calendar events’).

Indicators of Compromise

  • [Domain] DNS recovery and C2 infrastructure – cloudlanecdn[.]com, ns1.cloudlanecdn[.]com, and 2 more nameservers
  • [IP Address] Authoritative DNS infrastructure – 216.126.237[.]197, 144.172.108[.]205, and other shared IPs
  • [File Hash] Malware module samples – CAF021DDA726B8BA049C2AA395E505A1, C092B02FBC0FDF7EE9608DD016673806, and 1 more hash
  • [File Name] CAV3RN communication component – AzureCommunication.dll, NewProject.dll, and other referenced binaries
  • [File Name] Local configuration cache – logAzure.txt
  • [IP Address] Sentinel AAAA response used for failure handling – 2001:4998:44:3507::8000
  • [Domain] Related domains mentioned in infrastructure context – google.com[.]ayalon-print.co[.]il, clipeditskill[.]com, and accesslinkssl[.]com


Read more: https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/