Executive Summary
In June 2026, Kaspersky's Threat Intelligence Reporting service detailed Project CAV3RN, a sophisticated modular cyberespionage framework targeting Israeli entities. Active since December 2025, the framework underwent a significant architectural shift in April 2026, transitioning from a three-component system to a controller-based architecture with a WebSocket-enabled C2 communication component and an extensible plugin system. Subsequently, a new .NET Native AOT communication module was identified, utilizing Outlook calendar events accessed via Microsoft Graph for command and control (C2) communications. This module also employs a DNS AAAA-based recovery mechanism to retrieve configuration settings if Microsoft Graph authentication fails. (securelist.com)
The emergence of Project CAV3RN underscores the evolving tactics of state-sponsored threat actors, particularly the Iranian-linked group APT34 (OilRig). Their innovative use of legitimate services like Microsoft Graph and DNS for covert communications highlights the need for organizations to enhance monitoring of cloud services and implement robust detection mechanisms to identify and mitigate such sophisticated threats.
Why This Matters Now
The innovative use of legitimate services like Microsoft Graph and DNS for covert communications by state-sponsored threat actors like APT34 (OilRig) underscores the urgent need for organizations to enhance monitoring of cloud services and implement robust detection mechanisms to identify and mitigate such sophisticated threats.
Attack Path Analysis
The attackers gained initial access by exploiting vulnerabilities in public-facing applications, allowing them to deploy the Project CAV3RN framework. They then escalated privileges by obtaining valid credentials through credential dumping techniques. Utilizing these credentials, they moved laterally within the network to access additional systems. For command and control, they established communication channels using Outlook calendar events accessed via Microsoft Graph API. Data exfiltration was conducted by embedding sensitive information within calendar event attachments, which were then retrieved by the attackers. The impact of the attack included unauthorized access to sensitive data and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
The attackers exploited vulnerabilities in public-facing applications to deploy the Project CAV3RN framework.
MITRE ATT&CK® Techniques
Application Layer Protocol: DNS
Dynamic Resolution: DNS Calculation
Application Layer Protocol: Web Protocols
Proxy: Internal Proxy
Ingress Tool Transfer
Data Obfuscation: Protocol Impersonation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing firewalls are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement network segmentation and monitoring to detect and prevent unauthorized access.
Control ID: Pillar 3: Network and Environment
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Practice/Law Firms
CAV3RN cyberespionage framework directly compromised Israeli law firm Microsoft 365 mailbox for command-and-control, enabling lateral movement and data exfiltration.
Legal Services
Outlook calendar event C2 communication bypasses traditional security controls, threatening confidential client data through encrypted traffic and east-west movement.
Government Administration
State-sponsored cyberespionage targeting creates significant risks for government entities through zero trust segmentation vulnerabilities and multicloud visibility gaps.
Information Technology/IT
Cloud native security fabric weaknesses enable sophisticated DNS AAAA configuration recovery mechanisms, compromising Microsoft Graph authentication and Kubernetes security.
Sources
- New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoveryhttps://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in public-facing applications would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges using obtained credentials would likely be constrained, reducing the risk of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of accessing additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of persistent external communication.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to cause significant impact would likely be constrained, reducing the risk of widespread data breaches and service disruptions.
Impact at a Glance
Affected Business Functions
- Legal Document Management
- Client Communications
- Case Management
Estimated downtime: 7 days
Estimated loss: $50,000
Confidential client information, legal case files, and sensitive communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust egress security and policy enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance east-west traffic security to detect and prevent lateral movement within the network.
- • Deploy zero trust segmentation to enforce least privilege access and limit the spread of potential intrusions.
- • Utilize multicloud visibility and control solutions to monitor and manage activities across cloud environments.
- • Establish threat detection and anomaly response mechanisms to identify and respond to suspicious activities promptly.



