Kaspersky GReAT researchers detail a newly identified .NET Native AOT C2 communication module belonging to Project CAV3RN, a cyberespionage framework attributed with low confidence to OilRig (APT34). The module, AzureCommunication.dll, replaces the previous HTTP/WebSocket component by routing commands and results through Outlook calendar events via Microsoft Graph API. Commands are encrypted with RSA-OAEP-SHA256 and AES-256-GCM, stored as attachments on calendar events scheduled in 2050 to avoid detection. When Microsoft Graph authentication fails, the module falls back to a DNS AAAA-based configuration recovery protocol, querying actor-controlled authoritative nameservers at cloudlanecdn[.]com to retrieve replacement tenant credentials encoded in IPv6 address bytes. The report includes detailed protocol analysis of both the Graph-based C2 channel and the DNS recovery mechanism, infrastructure timeline, and attribution evidence linking behavioral patterns to previously documented OilRig tooling.