Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Project CAV3RN .NET Native AOT communication module

0
Medium
Published: 07/21/2026 (07/21/2026, 11:19:50 UTC)
Source: AlienVault OTX General

Description

Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 08:39:09 UTC

Technical Analysis

Kaspersky identified a new communication module for Project CAV3RN, a cyberespionage framework targeting Israel. The module uses .NET Native AOT and communicates by embedding commands and results in Outlook calendar events accessed through Microsoft Graph API, replacing prior HTTP/WebSocket methods. Communications are encrypted with RSA and AES-GCM. When authentication to Microsoft Graph fails, the module retrieves replacement configuration via DNS AAAA records from attacker-controlled nameservers. Infrastructure and behavioral indicators suggest a low-confidence attribution to OilRig (APT34), leveraging Microsoft-hosted services and compromised regional infrastructure for command and control.

Potential Impact

This malware enables stealthy command and control communications through legitimate Microsoft services (Outlook calendar via Microsoft Graph API) and fallback DNS queries, potentially evading detection. It facilitates cyberespionage activities targeting Israeli entities. The use of strong encryption (RSA and AES-GCM) protects the confidentiality and integrity of commands and data exchanged. The fallback mechanism via DNS AAAA records increases resilience against disruption of primary communication channels.

Mitigation Recommendations

No official patch or remediation is applicable as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed domains and hashes. Awareness of this threat and its use of Microsoft Graph API and DNS for command and control can guide detection and response efforts. Since this is a targeted espionage tool, organizations in Israel and related sectors should apply enhanced monitoring of Outlook calendar events and DNS traffic for suspicious patterns. Patch status is not applicable; check vendor advisories and threat intelligence updates for detection signatures and mitigation strategies.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/"]
Adversary
CHRYSENE
Pulse Id
6a5f55d6d75eaa9d17122eea
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincloudlanecdn.com
domainclipeditskill.com
domainaccesslinkssl.com
domaind.53466d4c67515a.0.p.cloudlanecdn.com
domaingoogle.com.ayalon-print.co.il
domainns1.cloudlanecdn.com
domainns2.cloudlanecdn.com
domainns3.cloudlanecdn.com
domainns4.cloudlanecdn.com

Hash

ValueDescriptionCopy
hash75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509
hashb3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff
hashf3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3
hash29b2b8c5d99f05bfcdd0d8d976eb5678
hashc092b02fbc0fdf7ee9608dd016673806
hashcaf021dda726b8ba049c2aa395e505a1
hash66c8a4d782ec9e19d67f426376e0ebb5af868590
hash83ed3f17a83b083246f90011d33861cdb5734ab3
hashbeb57441b81e56d1d7ba72acd841f2ffe171a325

Threat ID: 6a607dae9c2644c7f8ac06c2

Added to database: 07/22/2026, 08:22:06 UTC

Last enriched: 07/22/2026, 08:39:09 UTC

Last updated: 07/23/2026, 00:18:44 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses