Project CAV3RN is a modular cyberespionage framework used in operations targeting organizations in Israel. Activity associated with the framework has been tracked since late 2025 and remained active through at least mid-2026, with clear evidence of ongoing development and architectural refinement. The framework initially appeared as a simpler downloader-executor-uploader chain, but later evolved into a controller-and-plugin architecture. In its more mature form, a central controller manages agent identity, polling, task routing, and built-in commands, while separate modules provide communications and extensible functionality. This progression indicates a deliberate effort to improve operational flexibility, resilience, and maintainability. A notable Project CAV3RN communications component uses Microsoft Graph to access Outlook calendar data in a compromised Microsoft 365 mailbox and turns calendar events into a dead-drop command-and-control channel. Operators place encrypted tasking in specially formatted calendar events, and infected systems retrieve, decrypt, and remove those events before returning encrypted execution results through attachments in newly created events. The use of far-future event dates reduces visibility in normal user workflows and helps conceal malicious activity inside legitimate cloud services. The framework also incorporates a fallback recovery mechanism based on DNS AAAA-record queries. If cloud authentication or tenant validation fails, the malware can reconstruct replacement Microsoft 365 configuration values from data encoded in DNS responses served by actor-controlled infrastructure. This secondary channel is designed to restore access to the primary cloud-based command path rather than replace it entirely, demonstrating an emphasis on persistence and operational continuity. Observed tradecraft includes abuse of trusted cloud platforms for command and control, encrypted attachment-based task exchange, modular plugin execution, heartbeat signaling, and redundant communications design. The malware uses strong cryptographic protections for command delivery and result exfiltration, limiting visibility into tasking and helping ensure that only the operators can decrypt returned data. Project CAV3RN has been linked by some researchers to the activity cluster also referred to as Cavern Manticore. There is low-confidence assessment of an association with the Iran-aligned threat actor OilRig, also known as APT34, based on behavioral and operational similarities such as espionage targeting aligned with Israeli interests, use of Microsoft-hosted services for command and control, attachment-based exchanges, and mechanisms to recover cloud C2 access. However, direct code-reuse evidence publicly tying Project CAV3RN to OilRig has not been established, so that attribution should be treated as provisional rather than confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage activity cluster targeting organizations in Israel using a modular framework with a Microsoft Graph-based Outlook calendar dead-drop C2 channel and DNS AAAA-record fallback for configuration recovery.
A cyberespionage activity cluster using a modular framework against targets in Israel. The latest observed module uses Microsoft Graph and Outlook calendar events as a C2 channel, with DNS AAAA-based fallback to recover Graph configuration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.