Securelist CAV3RN Framework Upgrades to Outlook Calendar for C2 Communication
Article Content
- •CAV3RN's new module uses Outlook calendar events for stealthy C2 communication.
- •The framework targets entities in Israel and has been active since late 2025.
- •The upgrade enhances modular capabilities and avoids detection by traditional methods.
The Project CAV3RN cyberespionage framework has evolved with the introduction of a new communication module, AzureCommunication.dll, which replaces the previous HTTP/WebSocket component. This module utilizes Outlook calendar events accessed via Microsoft Graph for command and control (C2) communication, enhancing its stealth capabilities. Additionally, it employs DNS AAAA records for configuration recovery. The framework has been active against targets in Israel since December 2025, with significant changes noted in April 2026. This shift to a controller-based architecture allows for more modular post-exploitation capabilities. The new communication method aims to avoid detection while maintaining operational effectiveness. The full implications of this upgrade are still being analyzed, and further public research is expected to emerge.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Lyceum, Cav3rn and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over 15 government webmail accounts across multiple countries in the Middle East and Asia. Their…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…