Intel Node
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
Introduction In June 2026, as part of our Kaspersky Threat Intelligence Reporting service , we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel.
We have been tracking this cluster since December 2025, and in late April 2026, we observed a major architectural shift: the developers moved from a three-component framework consisting of a downloader, executor, and uploader to a controller-based architecture with a dedicated WebSocket-enabled C2 communication component and a more extensible plugin system designed to support modular post-exploitation capabilities. Subsequently, Check Point Research publicly reported on the same controller-based architecture in July 2026.