⚠️ Region Alert: UAE/Middle East
Project CAV3RN, a sophisticated cyberespionage framework attributed with low confidence to OilRig (APT34), has undergone a significant architectural shift. Kaspersky's analysis reveals a new .NET Native AOT communication module designed to replace previous HTTP/WebSocket components. This module leverages Microsoft Graph to use Outlook calendar events as a covert Command and Control (C2) channel, scheduling events in the year 2050 to avoid detection. Commands are transmitted via encrypted attachments within these calendar events, utilizing RSA and AES-GCM for robust encryption and decryption.
A critical feature of this updated module is its robust configuration recovery mechanism. Should Microsoft Graph authentication or tenant validation fail, the module employs a unique DNS AAAA record protocol to retrieve replacement connection settings, including tenant ID, client ID, client secret, and user email. This fallback system uses actor-controlled authoritative nameservers to dynamically supply fragmented configuration data through specially crafted DNS queries, demonstrating the attackers' ingenuity in maintaining persistent access.
The behavioral patterns observed in this new module, such as the use of Microsoft-hosted services for C2, attachment-based command exchange, and a secondary mechanism for restoring cloud C2 access, strongly align with known OilRig (APT34) tactics. This ongoing evolution, with significant changes between December 2025 and May 2026, highlights the active development and adaptation of the CAV3RN framework, underscoring the persistent threat it poses, particularly to targets in the Middle East.
Top comments (0)