PROJECT CAV3RN is a cyberespionage framework, linked to the Iran-based group OilRig (APT34), targeting organizations in Israel, including an Israeli law firm. Discovered by Kaspersky, its new communication module uses Microsoft Outlook calendar events to hide commands, making detection challenging. The framework has evolved into a controller-and-plugin design and employs encrypted calendar entries to manage commands. A fallback method using DNS queries is utilized if Microsoft Graph login fails.
Kaspersky has low confidence in its attribution to OilRig, despite similar tactics previously employed by the group. The framework poses risks of data exposure rather than theft, underscoring a trend in using trusted cloud services for espionage.