securelist · Crawled Jul 31, 2026
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
13 IoCs 1 Actors
Read original article ↗
AI Summary
Project CAV3RN is a modular cyberespionage framework targeting entities in Israel, with activity observed since December 2025. A newly identified .NET Native AOT communication module, AzureCommunication.dll, replaces previous HTTP/WebSocket-based C2 by using Microsoft Graph to exchange commands and results via Outlook calendar events. If authentication fails, the module recovers configuration data through DNS AAAA record queries to actor-controlled nameservers. The framework demonstrates advanced resilience and operational continuity through fallback mechanisms and use of legitimate cloud services.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | caf021dda726b8ba049c2aa395e505a1 | Details → |
| MD5 | c092b02fbc0fdf7ee9608dd016673806 | Details → |
| MD5 | 29b2b8c5d99f05bfcdd0d8d976eb5678 | Details → |
| Domain | cloudlanecdn[.]com | Details → |
| Domain | ns1[.]cloudlanecdn[.]com | Details → |
| Domain | ns2[.]cloudlanecdn[.]com | Details → |
| Domain | ns3[.]cloudlanecdn[.]com | Details → |
| Domain | ns4[.]cloudlanecdn[.]com | Details → |
| Domain | google[.]com[.]ayalon-print[.]co[.]il | Details → |
| Domain | clipeditskill[.]com | Details → |
| Domain | accesslinkssl[.]com | Details → |
| IP | 216[.]126[.]237[.]197 | Details → |
| IP | 144[.]172[.]108[.]205 | Details → |
MITRE ATT&CK TTPs 29 techniques
T1001.002 Steganography · Command And Control T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1102 Web Service · Command And Control T1105 Ingress Tool Transfer · Command And Control T1114 Email Collection · Collection T1132.001 Standard Encoding · Command And Control T1204.002 Malicious File · Execution T1558 Steal or Forge Kerberos Tickets · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1583 Acquire Infrastructure · Resource Development T1588 Obtain Capabilities · Resource Development