Summary
Key Points:
- Project CAV3RN, a cyberespionage framework attributed to OilRig (APT34), has evolved to use Outlook calendar events for command and control (C2) communication, replacing its previous HTTP/WebSocket component.
- The new module, AzureCommunication.dll, employs Microsoft Graph for communication and uses DNS AAAA records for configuration recovery, potentially impacting Microsoft 365 environments and organizations utilizing Outlook.
- Immediate actions include monitoring for unusual calendar events in Microsoft 365 accounts, implementing strict access controls, and reviewing DNS configurations for anomalies.
Technical Details: The AzureCommunication.dll module utilizes Microsoft Graph API to exchange commands via Outlook calendar events. If authentication fails, it retrieves configuration settings through actor-controlled DNS AAAA responses.
MITRE ATT&CK Techniques:
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1046 - Network Service Discovery (Discovery)
- T1070.001 - Indicator Removal on Host: File Deletion (Defense Evasion)
IOCs Mentioned:
- File hashes: CAF021DDA726B8BA049C2AA395E505A1, C092B02FBC0FDF7EE9608DD016673806, 29B2B8C5D99F05BFCDD0D8D976EB5678
- Domains: cloudlanecdn.com, ns1.cloudlanecdn.com, ns2.cloudlanecdn.com, ns3.cloudlanecdn.com, ns4.cloudlanecdn.com
- IPs: 216.126.237.197, 144.172.108.205
Join the discussion — sign up to comment, upvote, and save articles.