> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
- URL: https://f4n6.co.uk/security-feed/new-project-cav3rn-module-abuses-outlook-calendar-events-for-c2-and-dns-aaaa-records-for-configuration-recovery/
- Published: 2026-07-21T09:26:28.000Z
- Updated: 2026-07-21T09:26:28.000Z
- Author: Jeff Davies
- Tags: #security-feed, Project CAV3RN

## 1\. Executive summary

Kaspersky has published analysis of a new .NET Native AOT communication module (`AzureCommunication.dll`) within the Project CAV3RN cyberespionage framework, targeting entities in Israel. The module replaces prior HTTP/WebSocket C2 channels with Microsoft Graph API calls that exchange commands and results through Outlook calendar events scheduled in 2050, rendering them invisible in standard calendar views. If Microsoft Graph authentication fails, the module falls back to a novel DNS AAAA-record protocol to retrieve replacement Entra ID credentials from actor-controlled nameservers. Attribution to OilRig (APT34) remains unconfirmed — the actor "Project CAV3RN" has no MITRE ATT&CK profile, and Kaspersky assesses the OilRig link at low confidence with no direct code reuse or infrastructure overlap. EMEA financial services with Israeli operations or Microsoft 365 tenants should audit Graph API activity and DNS egress for the described indicators.

## 2\. Regulatory framing

| Article                                                 | Trigger (the fact in this item)                                                                                                                                                                            | Practical impact                                                                                                                                                                                        |
| ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 17: ICT-related incident management process   | The module compromises a Microsoft 365 mailbox belonging to an Israeli law firm and abuses it as a C2 dead-drop, meaning a third-party cloud service is actively weaponised within the incident lifecycle. | Financial entities must ensure their ICT incident management process accounts for cloud-service abuse as an incident vector and can detect/respond to malicious Graph API use within their own tenants. |
| DORA Art. 28: ICT third-party risk — general principles | The C2 channel operates entirely through Microsoft Graph / Microsoft 365, a critical ICT third-party service provider, using legitimate API endpoints and OAuth tokens to evade network controls.          | Entities must review whether their ICT third-party risk controls extend to monitoring for abuse of legitimate cloud API channels, not just outages or provider-side breaches.                           |

## 3\. Technical analysis & attack chain

**Attribution caveat:** Actor "Project CAV3RN" has no MITRE ATT&CK profile; attribution is unconfirmed. Kaspersky assesses a low-confidence link to OilRig/APT34 based on behavioural parallels (Microsoft-hosted C2, attachment-based command exchange, secondary recovery mechanisms, use of compromised regional infrastructure) but identified no direct code reuse or infrastructure overlap. The following analysis is single-sourced to Kaspersky's reporting; verify before enforcement.

### Attack chain (confirmed steps from source)

1. **Controller loading:** An updated controller (not yet recovered) loads `AzureCommunication.dll`, resolves its single export `QueryInterface`, and passes a null-terminated UTF-16 string in the format `get_;;_<agent-id>,_<legacy-url>` or `send_;;_<agent-id>,_<legacy-url>,_<result>`. The `_;;_` delimiter separates operation from arguments; `_,` separates arguments. The legacy URL is ignored for compatibility.
2. **Configuration initialisation:** The module checks for a relative file `logAzure.txt` in the host process's current working directory. If present, it deserialises the file. If absent, it builds configuration from hardcoded values and writes them to disk. The configuration contains: Microsoft Entra tenant ID, client ID, client secret, compromised target mailbox (`***@*********.co.il`), DNS bootstrap domain (`cloudlanecdn[.]com`), an RSA public key (outbound encryption), and an RSA private key (inbound decryption).
3. **Graph authentication:** The module creates a Microsoft Graph client and validates access via `GET https://graph.microsoft.com/v1.0/organization`. The Azure Identity library obtains an OAuth application token via `POST https://login.microsoftonline.com/<TenantId>/oauth2/v2.0/token` with `client_id`, `client_secret`, `scope=https://graph.microsoft.com/.default`, `grant_type=client_credentials`. The token is included in subsequent requests as `Authorization: Bearer <access-token>`.
4. **Command retrieval (`get`):** The module queries the default calendar of the compromised mailbox for events in a fixed one-hour window: `2050-05-13T22:00:00` to `2050-05-13T23:00:00` UTC. It filters by subject using `GET /v1.0/users/<mailbox>/calendarView?startDateTime=2050-05-13T22:00:00&endDateTime=2050-05-13T23:00:00&$filter=contains(subject,'Event ID: <agent-id>')`. The 2050 date ensures events do not appear in ordinary calendar views.
5. **Attachment download and event deletion:** If a matching event is found, the module downloads attachments via `GET /v1.0/users/<mailbox>/events/<EventId>/attachments`, then deletes the event via `DELETE /v1.0/users/<mailbox>/calendar/events/<EventId>`. Inbound command attachments are named `file0.txt` (lowercase 'f').
6. **Command decryption:** Inbound commands use hybrid RSA + AES-256-GCM encryption. The reconstructed buffer begins with a 256-byte RSA-encrypted block containing the 32-byte AES key, decrypted using RSA-OAEP with SHA-256 and the configured private key. The next 12 bytes are the AES-GCM nonce; the final 16 bytes are the authentication tag; the intervening bytes are ciphertext. A decrypted 63-byte example produces: `{"cid": "alXBCzcDl8hBuNE", "type": "self", "cmd": "003_;;__,_"}`. The `cid` field is a command-correlation identifier. When `type` is `self`, the controller routes to its internal handler; `cmd` `003` toggles debug logging.
7. **Result exfiltration (`send`):** The module encrypts command output with a freshly generated AES-256-GCM key, protects that key with the configured RSA public key, and divides the payload into chunks of up to 10 MiB. It creates a calendar event with temporary subject `d`, uploads chunks as sequentially named attachments (`File0.txt`, `File1.txt` — uppercase 'F'), then changes the subject to `Boss Report ID: <agent-id>1500`. The sequence is: `POST /v1.0/users/<mailbox>/calendar/events`, `POST /v1.0/users/<mailbox>/calendar/events/<EventId>/attachments`, `PATCH /v1.0/users/<mailbox>/events/<EventId>`.
8. **Heartbeat maintenance:** The module searches the fixed calendar window for a previous event with subject `Boss update ID: <agent-id>1500`. If found, it deletes it and creates a replacement with temporary subject `d`, then patches the subject to `Boss update ID: <agent-id>1500`. Heartbeat events contain no attachments. The suffix `1500` is fixed and not part of the Agent ID.
9. **DNS AAAA fallback (if Graph auth fails):** When OAuth token acquisition or the `/organization` validation request fails, the module queries `cloudlanecdn[.]com` (delegated to `ns1`–`ns4.cloudlanecdn[.]com`) for replacement `TenantId`, `ClientId`, `ClientSecret`, and `UserEmail`. The seven-character Agent ID is converted to uppercase hexadecimal (e.g., `SFmLgQZ` → `53466D4C67515A`). For each field, a length query is sent: `d.<hex-agent-id>.<field-index>.p.cloudlanecdn[.]com` (indices: 0=TenantId, 1=ClientId, 2=ClientSecret, 3=UserEmail). The AAAA response's first two bytes are discarded; the next two bytes are interpreted as a big-endian field length. Data queries follow: `d.<hex-agent-id>.<field-index>.<offset>.q.cloudlanecdn[.]com`. Each `.q.` response provides up to 14 bytes (first two bytes discarded). The sentinel address `2001:4998:44:3507::8000` (Yahoo's allocation) signals failure; the module raises an exception and does not process the response. Recovered values are decoded as UTF-8, written to `logAzure.txt`, and a new Graph client is created.

### Subject format summary

| Subject format                 | Purpose                   | Behaviour                                                           |
| ------------------------------ | ------------------------- | ------------------------------------------------------------------- |
| Event ID: <agent-id>           | Operator-to-agent command | Downloads attachments, deletes event after consumption              |
| Boss update ID: <agent-id>1500 | Agent heartbeat           | Deletes previous heartbeat, creates replacement                     |
| Boss Report ID: <agent-id>1500 | Agent-to-operator output  | Creates event, uploads encrypted attachments, assigns final subject |

## 4\. Mitigation & containment

### P1 — within 24 hours

- **Block DNS infrastructure:** Block queries to `cloudlanecdn[.]com` and all four nameserver hostnames (`ns1[.]cloudlanecdn[.]com` through `ns4[.]cloudlanecdn[.]com`) at recursive resolvers. Block IPs `216[.]126[.]237[.]197` and `144[.]172[.]108[.]205` (AS14956, RouterHosting LLC).
- **Hunt for module files:** Search endpoints for `AzureCommunication.dll`, `NewProject.dll`, `uxtheme.dll` (in non-standard locations), `n-HTCommp.dll`, and `logAzure.txt`. Hashes to match:
- `CAF021DDA726B8BA049C2AA395E505A1` (AzureCommunication.dll)
- `29B2B8C5D99F05BFCDD0D8D976EB5678` (AzureCommunication.dll, second sample)
- `C092B02FBC0FDF7EE9608DD016673806` (NewProject.dll)
- **Graph API audit:** Query Microsoft 365 audit logs for application-level access to `/v1.0/users/<mailbox>/calendarView` and `/v1.0/users/<mailbox>/calendar/events` with `client_credentials` grant type. Look for calendar events with subjects matching `Event ID:`, `Boss update ID:`, or `Boss Report ID:` and events scheduled in 2050.
- **Block related domains:** `clipeditskill[.]com`, `accesslinkssl[.]com`, `google.com[.]ayalon-print.co[.]il`.

### P2 — within 72 hours

- **Entra ID application review:** Audit all registered applications in Entra ID for those with `Mail.ReadWrite`, `Calendars.ReadWrite`, or `Files.ReadWrite.All` application permissions using client\_credentials flow. Disable and investigate any unrecognised applications.
- **Conditional access hardening:** Restrict Graph API access from unmanaged or non-compliant devices. Implement location-based conditional access policies for application-level Graph API calls where feasible.
- **DNS egress monitoring:** Deploy DNS query logging for AAAA requests matching the pattern `d.*.[0-3].*.cloudlanecdn[.]com` or similar subdomain patterns with hex-encoded agent IDs. Monitor for AAAA responses where the first hextet is `2001` and the response is not a legitimate IPv6 address.
- **EDR rules:** Create detection rules for processes loading DLLs via `QueryInterface` export with command strings containing `_;;_` delimiters.

### P3 — within 7 days

- **Calendar event hunting:** Run Microsoft Graph queries across all mailboxes for calendar events with start dates in 2050, particularly within the 22:00–23:00 UTC window. Export and review subjects matching the known patterns.
- **Review OAuth application governance:** Implement a periodic review process for all Entra ID applications with mail/calendar application permissions. Remove unused or unrecognised app registrations.
- **Threat hunt for `logAzure.txt`:** Search file shares, endpoint workstations, and servers for `logAzure.txt` files containing JSON with `TenantId`, `ClientId`, `ClientSecret`, `UserEmail`, `Host`, `PublicKey`, and `PrivateKey` fields.

## 5\. Indicators of compromise

| Type     | Value                                 | Confidence | Source    |
| -------- | ------------------------------------- | ---------- | --------- |
| md5      | CAF021DDA726B8BA049C2AA395E505A1      | High       | Kaspersky |
| md5      | C092B02FBC0FDF7EE9608DD016673806      | High       | Kaspersky |
| md5      | 29B2B8C5D99F05BFCDD0D8D976EB5678      | High       | Kaspersky |
| domain   | cloudlanecdn\[.\]com                  | High       | Kaspersky |
| domain   | ns1\[.\]cloudlanecdn\[.\]com          | High       | Kaspersky |
| domain   | ns2\[.\]cloudlanecdn\[.\]com          | High       | Kaspersky |
| domain   | ns3\[.\]cloudlanecdn\[.\]com          | High       | Kaspersky |
| domain   | ns4\[.\]cloudlanecdn\[.\]com          | High       | Kaspersky |
| domain   | google.com\[.\]ayalon-print.co\[.\]il | Medium     | Kaspersky |
| domain   | clipeditskill\[.\]com                 | Medium     | Kaspersky |
| domain   | accesslinkssl\[.\]com                 | Medium     | Kaspersky |
| ipv4     | 216\[.\]126\[.\]237\[.\]197           | High       | Kaspersky |
| ipv4     | 144\[.\]172\[.\]108\[.\]205           | High       | Kaspersky |
| filename | AzureCommunication.dll                | High       | Kaspersky |
| filename | NewProject.dll                        | High       | Kaspersky |
| filename | logAzure.txt                          | High       | Kaspersky |
| filename | uxtheme.dll                           | High       | Kaspersky |
| filename | n-HTCommp.dll                         | High       | Kaspersky |

```iocs
md5  CAF021DDA726B8BA049C2AA395E505A1
md5  C092B02FBC0FDF7EE9608DD016673806
md5  29B2B8C5D99F05BFCDD0D8D976EB5678
domain  cloudlanecdn[.]com
domain  ns1[.]cloudlanecdn[.]com
domain  ns2[.]cloudlanecdn[.]com
domain  ns3[.]cloudlanecdn[.]com
domain  ns4[.]cloudlanecdn[.]com
domain  google.com[.]ayalon-print.co[.]il
domain  clipeditskill[.]com
domain  accesslinkssl[.]com
ipv4  216[.]126[.]237[.]197
ipv4  144[.]172[.]108[.]205
filename  AzureCommunication.dll
filename  NewProject.dll
filename  logAzure.txt
filename  uxtheme.dll
filename  n-HTCommp.dll

```

### Behavioural indicators

| Behaviour                                                                                                                                           | Where to observe                                        | Confidence |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------- | ---------- |
| OAuth client\_credentials flow to login.microsoftonline.com followed by Graph API GET /v1.0/organization                                            | Entra ID sign-in logs; proxy/IDS                        | High       |
| Graph API calendarView queries with startDateTime=2050-05-13T22:00:00 and endDateTime=2050-05-13T23:00:00                                           | Microsoft 365 audit logs; Graph API logs                | High       |
| Calendar events created with subjects containing Event ID:, Boss update ID:, or Boss Report ID:                                                     | Microsoft 365 audit logs; mailbox audit logging         | High       |
| Calendar events with temporary subject d subsequently patched to Boss update ID: or Boss Report ID:                                                 | Microsoft 365 audit logs                                | High       |
| DNS AAAA queries matching pattern d.<hex-string>.<0-3>.p.<domain> or d.<hex-string>.<0-3>.<number>.q.<domain>                                       | DNS resolver logs; network monitoring                   | High       |
| Calendar event attachments named file0.txt (inbound) or File0.txt (outbound)                                                                        | Microsoft 365 audit logs                                | Medium     |
| File logAzure.txt written to working directory containing JSON with TenantId, ClientId, ClientSecret, UserEmail, Host, PublicKey, PrivateKey fields | EDR file creation monitoring; file integrity monitoring | High       |

## 6\. Detection

```yara
rule CAV3RN_AzureCommunication_Module {
    meta:
        author = "Adverse Trace"
        date = "2026-07-21"
        reference = "https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/"
        description = "Detects CAV3RN AzureCommunication.dll communication module"
    strings:
        $export = "QueryInterface" ascii
        $dll_name = "AzureCommunication.dll" ascii
        $log_file = "logAzure.txt" ascii
        $tenant = "TenantId" ascii
        $client_id = "ClientId" ascii
        $client_secret = "ClientSecret" ascii
        $user_email = "UserEmail" ascii
        $graph_org = "graph.microsoft.com/v1.0/organization" ascii
        $oauth = "oauth2/v2.0/token" ascii
        $grant = "client_credentials" ascii
        $calendar = "calendarView" ascii
        $event_subject = "Event ID:" ascii
        $heartbeat = "Boss update ID:" ascii
        $report = "Boss Report ID:" ascii
        $temp_subj = "Boss Report ID: " ascii
        $delimiter = "_;;_" ascii
        $file0 = "file0.txt" ascii
        $File0 = "File0.txt" ascii
        $sentinel = "2001:4998:44:3507::8000" ascii
        $recovery_p = ".p." ascii
        $recovery_q = ".q." ascii
        $attach_path = "/attachments" ascii
        $events_path = "/events" ascii
        $calendar_events = "/calendar/events" ascii
    condition:
        $export and ($dll_name or $log_file) and 4 of ($tenant, $client_id, $client_secret, $user_email) and 2 of ($graph_org, $oauth, $grant, $calendar) and 2 of ($event_subject, $heartbeat, $report, $temp_subj) and $delimiter
}

rule CAV3RN_LogAzure_Config {
    meta:
        author = "Adverse Trace"
        date = "2026-07-21"
        reference = "https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/"
        description = "Detects CAV3RN logAzure.txt configuration file"
    strings:
        $tenant = "TenantId" ascii
        $client_id = "ClientId" ascii
        $client_secret = "ClientSecret" ascii
        $user_email = "UserEmail" ascii
        $host = "Host" ascii
        $pubkey = "PublicKey" ascii
        $privkey = "PrivateKey" ascii
        $rsa_pub = "BEGIN RSA PUBLIC KEY" ascii
        $rsa_priv = "BEGIN RSA PRIVATE KEY" ascii
    condition:
        4 of ($tenant, $client_id, $client_secret, $user_email, $host) and 2 of ($pubkey, $privkey, $rsa_pub, $rsa_priv)
}

```

```yaml
title: CAV3RN Outlook Calendar C2 via Microsoft Graph API
id: 7a3c1f2e-4b5d-4a8e-9c1f-2d3e4f5a6b7c
status: experimental
description: Detects CAV3RN communication module using Microsoft Graph to access Outlook calendar events for C2, identified by calendar queries targeting 2050 dates and known subject patterns.
author: Adverse Trace
date: 2026/07/21
references:

    - https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
logsource:
    product: microsoft365
    service: audit
detection:
    selection_calendar_query:
        eventSource: "MicrosoftGraph"
        operationName|contains:

            - "calendarView"
        startDateTime|contains:

            - "2050-05-13T22:00:00"
    selection_event_subject:
        eventSource: "MicrosoftGraph"
        operationName|contains:

            - "calendar"
        Subject|contains:

            - "Event ID:"
            - "Boss update ID:"
            - "Boss Report ID:"
    selection_temp_subject:
        eventSource: "MicrosoftGraph"
        Subject: "d"
        operationName|contains:

            - "PATCH"
    condition: selection_calendar_query or selection_event_subject or selection_temp_subject
falsepositives:

    - Legitimate calendar events scheduled far in the future (unlikely with these subject patterns)
level: high

```

```yaml
title: CAV3RN DNS AAAA Configuration Recovery Queries
id: 8b4d2g3f-5c6e-4b9f-0d2g-3e4f5a6b7c8d
status: experimental
description: Detects CAV3RN DNS AAAA queries used for configuration recovery, matching the d.<hex>.<index>.p|q.<host> pattern.
author: Adverse Trace
date: 2026/07/21
references:

    - https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
logsource:
    product: dns
detection:
    selection_recovery:
        query_type: "AAAA"
        query|re: "d\.[0-9A-Fa-f]+\.[0-3]\.(p|q)\.cloudlanecdn\.com"
    condition: selection_recovery
falsepositives:

    - Unlikely; the query structure is highly specific to the CAV3RN recovery protocol
level: high

```

```yaml
title: CAV3RN logAzure.txt Configuration File Creation
id: 9c5e3h4g-6d7f-4c0f-1e3h-4f5a6b7c8d9e
status: experimental
description: Detects creation of logAzure.txt, the CAV3RN communication module's configuration persistence file.
author: Adverse Trace
date: 2026/07/21
references:

    - https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
logsource:
    product: windows
    category: file_event
detection:
    selection_file:
        TargetFilename|endswith: "logAzure.txt"
    condition: selection_file
falsepositives:

    - Unlikely; filename is specific to CAV3RN module
level: high

```

## 7\. Sources

- Kaspersky Securelist, "New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery," https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/, published 2026-07-21.

## 8\. Adverse Trace position

This advisory describes a sophisticated, actively developed C2 transport that abuses legitimate Microsoft Graph API endpoints and Outlook calendar events to evade network-based detection — a technique pattern that directly challenges financial services' reliance on perimeter egress controls. The DNS AAAA fallback protocol is novel and specifically designed to recover Entra ID credentials when primary authentication fails, making blocking of `cloudlanecdn[.]com` and its nameserver IPs a priority. Attribution to OilRig/APT34 remains unconfirmed (low confidence, single-sourced, no MITRE profile for "Project CAV3RN," no code reuse or infrastructure overlap); we treat the actor as unconfirmed and recommend clients do the same. The targeting scope (Israel) means EMEA financial services with Israeli operations, joint ventures, or shared Microsoft 365 tenants are at elevated risk. We will continue tracking CAV3RN development cycles and update clients if the unrecovered updated controller or additional plugins are identified. This advisory is single-sourced to Kaspersky's reporting; clients should verify indicators before enforcement actions.

---

[Read the original source →](https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*