All incidents

Project CAV3RN hides C2 commands in Outlook Calendar events for espionage

campaignopenJul 21, 2026 — Jul 21, 2026
Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel

RESEARCHERS have uncovered a new espionage framework, dubbed Project CAV3RN, that conceals its command‑and‑control traffic inside Microsoft Outlook calendar events to spy on Israeli organisations.

The framework leverages the Microsoft Graph API through a component named AzureCommunication.dll to write encrypted commands into the subject or body of calendar entries, which are then retrieved by the implanted malware.

If the Graph login fails, the malware falls back to a DNS AAAA query mechanism to receive configuration, allowing the controller‑plugin architecture to continue operating without raising obvious network alerts.

Kaspersky first observed activity on 21 July 2026 between 09:10 and 10:51 UTC, with targets including an Israeli law firm, and attributes the activity to a threat cluster tracked as CHRYSENE.

Although confidence in a direct link to the Iran‑based OilRig (APT34) group is low, the tactics mirror previous operations by that group and illustrate a growing trend of abusing trusted cloud services for stealthy command‑and‑control.

Defenders should enable detailed logging of Microsoft Graph interactions, watch for atypical calendar creation or modification events, and restrict OAuth consents to only approved applications to reduce the attack surface.

Monitoring DNS for unusual AAAA queries to uncommon domains, enforcing multi‑factor authentication on mailbox accounts, and regularly reviewing calendar sharing permissions can help detect and block this technique before data is exposed.

Intelligence briefing updated Jul 21, 2026

CHRYSENE
Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline