Project CAV3RN is a modular cyberespionage framework used in operations targeting organizations in Israel. It has also been tracked by another vendor as Cavern Manticore. Activity associated with the framework has been observed since late 2025, with the toolset evolving from a simple downloader-executor-uploader chain into a controller-and-plugin architecture by spring 2026, indicating active development and operational refinement. The framework’s controller manages agent identity, polling, built-in tasking, and plugin dispatch. A notable communication component, AzureCommunication.dll, uses Microsoft Graph and a compromised Microsoft 365 mailbox to exchange commands, heartbeats, and execution results through Outlook calendar events, effectively turning the mailbox into a dead-drop command-and-control channel. Commands are hidden in far-future calendar entries to reduce visibility in normal user workflows, then retrieved, decrypted, and deleted after use. Results are returned through encrypted attachments uploaded to corresponding calendar events. The framework uses hybrid cryptography combining RSA and AES-GCM to protect tasking and exfiltrated data. Project CAV3RN also includes a fallback recovery channel based on DNS AAAA queries. When cloud authentication or tenant validation fails, the malware reconstructs replacement Microsoft Graph configuration values from raw bytes embedded in IPv6 DNS responses. This design provides resilience and supports restoration of cloud-based command-and-control access if primary credentials or tenant settings become unusable. Observed tradecraft supports espionage-oriented post-compromise operations, including covert command execution, encrypted exfiltration, persistence of communications through legitimate cloud services, and defense evasion through abuse of trusted platforms and low-visibility data stores. The framework’s use of Microsoft-hosted services, attachment-based command exchange, and backup cloud-C2 recovery mechanisms has led to a low-confidence assessment linking it to the Iran-aligned threat actor OilRig, also known as APT34. That attribution remains unproven, with no direct code-reuse evidence publicly established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage activity cluster targeting organizations in Israel using a modular framework with a Microsoft Graph-based Outlook calendar dead-drop C2 channel and DNS AAAA-record fallback for configuration recovery.
A cyberespionage activity cluster using a modular framework against targets in Israel. The latest observed module uses Microsoft Graph and Outlook calendar events as a C2 channel, with DNS AAAA-based fallback to recover Graph configuration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.