New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
AI Analysis
Technical Summary
Kaspersky identified a new communication module for Project CAV3RN, a cyberespionage framework targeting Israel. The module uses .NET Native AOT and communicates by embedding commands and results in Outlook calendar events accessed through Microsoft Graph API, replacing prior HTTP/WebSocket methods. Communications are encrypted with RSA and AES-GCM. When authentication to Microsoft Graph fails, the module retrieves replacement configuration via DNS AAAA records from attacker-controlled nameservers. Infrastructure and behavioral indicators suggest a low-confidence attribution to OilRig (APT34), leveraging Microsoft-hosted services and compromised regional infrastructure for command and control.
Potential Impact
This malware enables stealthy command and control communications through legitimate Microsoft services (Outlook calendar via Microsoft Graph API) and fallback DNS queries, potentially evading detection. It facilitates cyberespionage activities targeting Israeli entities. The use of strong encryption (RSA and AES-GCM) protects the confidentiality and integrity of commands and data exchanged. The fallback mechanism via DNS AAAA records increases resilience against disruption of primary communication channels.
Mitigation Recommendations
No official patch or remediation is applicable as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed domains and hashes. Awareness of this threat and its use of Microsoft Graph API and DNS for command and control can guide detection and response efforts. Since this is a targeted espionage tool, organizations in Israel and related sectors should apply enhanced monitoring of Outlook calendar events and DNS traffic for suspicious patterns. Patch status is not applicable; check vendor advisories and threat intelligence updates for detection signatures and mitigation strategies.
Affected Countries
Israel
Indicators of Compromise
- domain: cloudlanecdn.com
- domain: clipeditskill.com
- domain: accesslinkssl.com
- hash: 75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509
- hash: b3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff
- hash: f3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3
- hash: 29b2b8c5d99f05bfcdd0d8d976eb5678
- hash: c092b02fbc0fdf7ee9608dd016673806
- hash: caf021dda726b8ba049c2aa395e505a1
- hash: 66c8a4d782ec9e19d67f426376e0ebb5af868590
- hash: 83ed3f17a83b083246f90011d33861cdb5734ab3
- hash: beb57441b81e56d1d7ba72acd841f2ffe171a325
- domain: d.53466d4c67515a.0.p.cloudlanecdn.com
- domain: google.com.ayalon-print.co.il
- domain: ns1.cloudlanecdn.com
- domain: ns2.cloudlanecdn.com
- domain: ns3.cloudlanecdn.com
- domain: ns4.cloudlanecdn.com
New Project CAV3RN .NET Native AOT communication module
Description
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kaspersky identified a new communication module for Project CAV3RN, a cyberespionage framework targeting Israel. The module uses .NET Native AOT and communicates by embedding commands and results in Outlook calendar events accessed through Microsoft Graph API, replacing prior HTTP/WebSocket methods. Communications are encrypted with RSA and AES-GCM. When authentication to Microsoft Graph fails, the module retrieves replacement configuration via DNS AAAA records from attacker-controlled nameservers. Infrastructure and behavioral indicators suggest a low-confidence attribution to OilRig (APT34), leveraging Microsoft-hosted services and compromised regional infrastructure for command and control.
Potential Impact
This malware enables stealthy command and control communications through legitimate Microsoft services (Outlook calendar via Microsoft Graph API) and fallback DNS queries, potentially evading detection. It facilitates cyberespionage activities targeting Israeli entities. The use of strong encryption (RSA and AES-GCM) protects the confidentiality and integrity of commands and data exchanged. The fallback mechanism via DNS AAAA records increases resilience against disruption of primary communication channels.
Mitigation Recommendations
No official patch or remediation is applicable as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the listed domains and hashes. Awareness of this threat and its use of Microsoft Graph API and DNS for command and control can guide detection and response efforts. Since this is a targeted espionage tool, organizations in Israel and related sectors should apply enhanced monitoring of Outlook calendar events and DNS traffic for suspicious patterns. Patch status is not applicable; check vendor advisories and threat intelligence updates for detection signatures and mitigation strategies.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/"]
- Adversary
- CHRYSENE
- Pulse Id
- 6a5f55d6d75eaa9d17122eea
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincloudlanecdn.com | — | |
domainclipeditskill.com | — | |
domainaccesslinkssl.com | — | |
domaind.53466d4c67515a.0.p.cloudlanecdn.com | — | |
domaingoogle.com.ayalon-print.co.il | — | |
domainns1.cloudlanecdn.com | — | |
domainns2.cloudlanecdn.com | — | |
domainns3.cloudlanecdn.com | — | |
domainns4.cloudlanecdn.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509 | — | |
hashb3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff | — | |
hashf3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3 | — | |
hash29b2b8c5d99f05bfcdd0d8d976eb5678 | — | |
hashc092b02fbc0fdf7ee9608dd016673806 | — | |
hashcaf021dda726b8ba049c2aa395e505a1 | — | |
hash66c8a4d782ec9e19d67f426376e0ebb5af868590 | — | |
hash83ed3f17a83b083246f90011d33861cdb5734ab3 | — | |
hashbeb57441b81e56d1d7ba72acd841f2ffe171a325 | — |
Threat ID: 6a607dae9c2644c7f8ac06c2
Added to database: 07/22/2026, 08:22:06 UTC
Last enriched: 07/22/2026, 08:39:09 UTC
Last updated: 07/23/2026, 00:18:44 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.