← Back to news

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky Securelist21/07/2026, 08:40
Read full article →

Summary

AI-Generated

Key Points:

  • Project CAV3RN, a cyberespionage framework attributed to OilRig (APT34), has evolved to use Outlook calendar events for command and control (C2) communication, replacing its previous HTTP/WebSocket component.
  • The new module, AzureCommunication.dll, employs Microsoft Graph for communication and uses DNS AAAA records for configuration recovery, potentially impacting Microsoft 365 environments and organizations utilizing Outlook.
  • Immediate actions include monitoring for unusual calendar events in Microsoft 365 accounts, implementing strict access controls, and reviewing DNS configurations for anomalies.

Technical Details: The AzureCommunication.dll module utilizes Microsoft Graph API to exchange commands via Outlook calendar events. If authentication fails, it retrieves configuration settings through actor-controlled DNS AAAA responses.

MITRE ATT&CK Techniques:

  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1046 - Network Service Discovery (Discovery)
  • T1070.001 - Indicator Removal on Host: File Deletion (Defense Evasion)

IOCs Mentioned:

  • File hashes: CAF021DDA726B8BA049C2AA395E505A1, C092B02FBC0FDF7EE9608DD016673806, 29B2B8C5D99F05BFCDD0D8D976EB5678
  • Domains: cloudlanecdn.com, ns1.cloudlanecdn.com, ns2.cloudlanecdn.com, ns3.cloudlanecdn.com, ns4.cloudlanecdn.com
  • IPs: 216.126.237.197, 144.172.108.205

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.