Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2026... we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Inbound commands use a combination of RSA and AES-GCM encryption... The communication module decrypts this block with the RSA private key stored in its configuration, using RSA-OAEP with SHA-256.
The malware downloads a command, decrypts it, then deletes the event.
If Microsoft Graph authentication or tenant validation fails, the module attempts to retrieve replacement connection settings through DNS AAAA responses.
Kaspersky found a new communication module for Project CAV3RN, an espionage framework aimed at Israel. It hides commands inside Outlook calendar events accessed through Microsoft Graph. | The new module, AzureCommunication.dll, replaces an older HTTP/WebSocket component. It turns a mailbox calendar into a dead drop.
The previously used communication component, n-HTCommp.dll, retrieved commands and transmitted execution results over HTTP/WebSocket.
If Microsoft Graph login or tenant checks fail, it queries DNS instead. It reads IPv6 AAAA answers as raw data, not as addresses.
Attackers favor trusted cloud services because they dodge simple network blocks. Microsoft Graph traffic rarely looks out of place.
It turns a mailbox calendar into a dead drop. Operators place commands in calendar events dated to the year 2050.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated modular cyberespionage framework targeting entities in Israel. It evolved from a downloader/executor/uploader design to a controller-based architecture with separate communication components and extensible plugins. The newly analyzed communication module uses Microsoft Graph and Outlook calendar events for C2, with DNS AAAA-based fallback to recover cloud connection settings.
A sophisticated modular cyberespionage framework targeting entities in Israel. It evolved from a downloader/executor/uploader design to a controller-based architecture with separate communication components and plugins. The newly analyzed communication module uses Microsoft Graph and Outlook calendar events as a dead-drop C2 channel, with DNS AAAA-based fallback to recover Graph configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.