CyberSecurity SEE

New CAV3RN Module Substitutes WebSocket C2 with Outlook Calendar Dead Drops

New CAV3RN Module Substitutes WebSocket C2 with Outlook Calendar Dead Drops

In a notable shift within the landscape of advanced cyberespionage, the Project CAV3RN tooling has seen the introduction of a new .NET Native AOT communication module known as AzureCommunication.dll. This module effectively replaces the previous HTTP/WebSocket component that was integral to the framework’s command-and-control (C2) operations. This evolution signifies a strategic move to establish a more covert communication channel that camouflages itself within legitimate Service networks, specifically leveraging Microsoft-hosted services.

Observers of cyber threat trends will recognize this strategic pivot as an alignment with the broader patterns exhibited by OilRig (APT34), notorious for employing Microsoft platforms to facilitate clandestine command-and-control mechanisms. By utilizing Outlook calendar events over Microsoft Graph and implementing a DNS-based recovery for Microsoft 365 credentials, the CAV3RN framework enhances its modular and stealthy capabilities.

This shift was recently highlighted by a public report from Check Point published in July 2026, confirming the layered structure of the modular framework—though it did not delve into the functionalities of the newly analyzed communication layer that has emerged.

AzureCommunication.dll, which has recently been spotted in the wild, retains the same controller-facing interface as its predecessor, showcasing a single export function, QueryInterface. This function accepts commands formatted in a familiar string format, preserving legacy parameters for compatibility while forsaking the HTTP/WebSocket communication in favor of Microsoft Graph’s calendar functionality. This allows CAV3RN operators to integrate their C2 actions more seamlessly with genuine Microsoft 365 traffic, further obscuring malicious intent.

Embedded within AzureCommunication.dll is a configuration object that includes sensitive information such as Microsoft Entra tenant identifiers, OAuth client credentials, and access to a compromised Outlook mailbox. The module also features a DNS bootstrap domain named cloudlanecdn[.]com, alongside RSA key pairs utilized to secure C2 communication, which are logged locally upon initial execution.

To authenticate and authorize actions, the module employs the Azure Identity stack to obtain an OAuth token through the client credentials flow, subsequently validating this access via queries directed at the organizational endpoint at graph.microsoft.com before undertaking any calendar operations. This sophisticated approach reaffirms the systemic use of Microsoft services for espionage.

Kaspersky’s June 2026 reporting on Project CAV3RN gives a more comprehensive view of its architecture, detailing a controller-based layout in which specific DLL files handle various communication functionalities. Notably, n-HTCommp.dll was responsible for managing C2 traffic, while uxtheme.dll directed commands to various plugins through a unique seven-character Agent ID.

In a distinctive operational approach, CAV3RN employs the default calendar of the compromised Outlook mailbox as a clandestine channel for C2 activities. All tasks are constrained within a defined one-hour window on May 13, 2050, from 22:00 to 23:00 UTC, cleverly designed to render events nearly invisible to casual observation.

Communication between the operator and agent occurs through scheduled calendar events, with subjects formatted in a specific way. For instance, operator-to-agent commands are categorized by event IDs, while heartbeat signals and results carry a Boss update ID. Essential to this architecture is the controlled naming convention that further blankets the framework’s activities in legitimate-looking metadata.

The inbound tasking process starts with a Microsoft Graph calendarView query, filtered to identify agent-specific subject lines. This is followed by the immediate deletion of any associated tasks once retrieved. Attachments, such as those named file0.txt, are utilized to carry commands from operators to agents, distributed across segments and secured through a hybrid cryptosystem.

The sophistication of the encryption and management of the intelligence being transferred underscores the relentless efforts of cyber operatives to secure their malicious frameworks. The use of RSA and AES encryption further amplifies the challenge for defenders trying to detect such activity.

As for tracking agent liveness, the system utilizes recurring heartbeat events lacking any attachments to minimize digital footprints while signaling operational activity. When lacks in Microsoft Graph authentication surface, AzureCommunication.dll reverts to a DNS-based fallback mechanism using cloudlanecdn[.]com—a critical detail that reflects the module’s flexibility and resilience.

Despite no direct code similarities or overlapping infrastructures being observed, the methods employed by CAV3RN resonate with the established tradecraft of OilRig. The synchronized behaviors with Microsoft-hosted services reinforce suspicions of a connection, especially as regional Microsoft 365 mailboxes are compromised for high-stakes espionage.

In light of these developments, cybersecurity professionals are urged to bolster their surveillance efforts around Microsoft Graph access patterns, including anomalous OAuth client IDs and unusual attachment-heavy events. Monitoring DNS traffic for encodings indicating recovery attempts from domains like cloudlanecdn[.]com is equally essential to preemptively address the growing sophistication of such cloud-centric command-and-control implants.

The evolution of Project CAV3RN encapsulates the emerging patterns of contemporary cyber threats, compelling defenders to adopt a more nuanced understanding of espionage techniques and advanced persistence threats.

Source link

Exit mobile version