Project CAV3RN is a modular cyberespionage framework used against entities in Israel and tracked since late 2025. It evolved from an earlier downloader-executor-uploader design into a controller-based architecture with interchangeable communication components and runtime-loadable plugins, indicating active ongoing development.
The framework supports covert command-and-control through multiple transport mechanisms. Documented communication modules include one that dynamically selects between direct HTTPS and a Google Apps Script relay based on DNS responses, and another that uses Microsoft Graph API with Outlook calendar events in a compromised Microsoft 365 mailbox as a dead-drop channel. The DNS-driven module can also validate and rotate relay configuration through DNS, while the Microsoft Graph-based module can recover replacement cloud authentication and mailbox configuration through DNS AAAA responses if cloud access fails. These designs show an emphasis on resilient, multi-transport communications and blending malicious traffic with legitimate cloud services.
Project CAV3RN includes a local broker component that discovers DLL-based modules, loads compatible components at runtime, routes messages among them, and supports upgrades when higher-version modules appear. Communication modules inventory local components and versions, exchange structured task packets, and can return broker-managed component listings to operators. Observed internal functionality includes configuration management, logging control, writing decoded payloads to disk, and encrypted command/result exchange using modern cryptography in the cloud-based channel.
The framework is associated with espionage activity rather than disruptive operations. Reported behavior supports post-compromise control, modular tasking, local orchestration, stealthy communications, and data return to operators. A low-confidence attribution to OilRig (APT34) has been suggested based on behavioral similarities, including use of Microsoft-hosted services and secondary recovery channels, but no direct code reuse or infrastructure overlap has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
cet article présente l’analyse technique d’un nouveau module de communication du framework Project CAV3RN, un outil de cyberespionnage modulaire suivi depuis décembre 2025 et ciblant des entités en Israël.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Components are grouped by CompanyName, and the highest-version candidate from each group is loaded if it exposes GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. The directory is rescanned every second, allowing a component to be added or upgraded without restarting the host.
T1027.009 — Obfuscated Files or Information: Embedded Payloads (Defense Evasion)
Inbound commands use a combination of RSA and AES-GCM encryption... The communication module decrypts this block with the RSA private key stored in its configuration, using RSA-OAEP with SHA-256.
The inter-component broker, rnp.dll, is a 64-bit DLL compiled with Microsoft Visual C++. ... It masquerades as the RNP OpenPGP library through numerous rnp_* exports
The malware downloads a command, decrypts it, then deletes the event.
If Graph returns one or more matches, the module selects the first returned event and requests its attachments... After obtaining the attachment response, the module deletes the calendar event.
Le module utilise le calendrier Outlook par défaut d’une boîte mail Microsoft 365 compromise ...
T1564.008 — Hide Artifacts: Email Hiding Rules (Defense Evasion)
Components are grouped by CompanyName, and the highest-version candidate from each group is loaded if it exposes GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. The directory is rescanned every second, allowing a component to be added or upgraded without restarting the host.
If Microsoft Graph authentication or tenant validation fails, the module attempts to retrieve replacement connection settings through DNS AAAA responses.
The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. | When DNS selects Direct HTTPS, the module contacts the configured ad address, https://api.studiotikva.com/api/v1/update/check, without using the relay.
C2 polling instead uses an outer POST to Apps Script whose "m":"GET" field instructs the relay to issue a GET request to its upstream server.
Before polling for commands or sending a result, the module performs a DNS A-record query to select Direct HTTPS or Google Apps Script.
The Google Apps Script deployment acted as an application-layer relay; during an upstream timeout, it exposed https://api.studiotikva.com/ac, revealing the actor-controlled backend endpoint.
The Google Apps Script deployment acted as an application-layer relay; during an upstream timeout, it exposed https://api.studiotikva[.]com/ac , revealing the actor-controlled backend endpoint.
Attackers favor trusted cloud services because they dodge simple network blocks. Microsoft Graph traffic rarely looks out of place.
It turns a mailbox calendar into a dead drop. Operators place commands in calendar events dated to the year 2050.
Le module utilise le calendrier Outlook par défaut d’une boîte mail Microsoft 365 compromise ... comme canal dead-drop via Microsoft Graph API.
The s_write command can replace these settings in memory but does not update the file... The module supports five internal commands... s_write Base64-decodes and GZip-decompresses provided data before writing it to the specified file path.
T1132.001 — Data Encoding: Standard Encoding (Command and Control)
The module also ships a fallback channel. If Microsoft Graph login or tenant checks fail, it queries DNS instead.
T1568.002 — Dynamic Resolution: Domain Generation Algorithms (Command and Control)
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular espionage framework targeting entities in Israel. It uses a local DLL broker and a multi-transport C2 module that can switch between direct HTTPS and a Google Apps Script relay based on DNS A-record responses. It supports runtime component discovery/loading, configuration updates, diagnostic logging, file writing, and DNS-based recovery/rotation of the Google Apps Script deployment ID.
A modular espionage framework targeting entities in Israel. It uses a local DLL broker to discover, load, and upgrade components at runtime, and a multi-transport C2 module that dynamically selects between direct HTTPS and a Google Apps Script relay based on DNS A-record responses. It inventories local DLLs, forwards broker tasks, supports in-memory reconfiguration, diagnostic logging, file writes, and DNS-based recovery/rotation of the Google Apps Script deployment ID.
A sophisticated modular cyberespionage framework targeting entities in Israel. It evolved from a downloader/executor/uploader design to a controller-based architecture with separate communication components and extensible plugins. The newly analyzed communication module uses Microsoft Graph and Outlook calendar events for C2, with DNS AAAA-based fallback to recover cloud connection settings.
Framework modulaire de cyberespionnage utilisant une architecture contrôleur-plugin. Le composant analysé emploie Microsoft 365 Outlook Calendar via Microsoft Graph API comme canal C2 dead-drop et dispose d’un mécanisme de récupération de configuration via requêtes DNS AAAA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.