Securelist
Read post

New Project CAV3RN .NET Native AOT communication module

Kaspersky GReAT researchers detail a newly identified .NET Native AOT C2 communication module belonging to Project CAV3RN, a cyberespionage framework attributed with low confidence to OilRig (APT34). The module, AzureCommunication.dll, replaces the previous HTTP/WebSocket component by routing commands and results through Outlook calendar events via Microsoft Graph API. Commands are encrypted with RSA-OAEP-SHA256 and AES-256-GCM, stored as attachments on calendar events scheduled in 2050 to avoid detection. When Microsoft Graph authentication fails, the module falls back to a DNS AAAA-based configuration recovery protocol, querying actor-controlled authoritative nameservers at cloudlanecdn[.]com to retrieve replacement tenant credentials encoded in IPv6 address bytes. The report includes detailed protocol analysis of both the Graph-based C2 channel and the DNS recovery mechanism, infrastructure timeline, and attribution evidence linking behavioral patterns to previously documented OilRig tooling.

    #.net#malware#dns
Jul 21•15m read time•From securelist.com
Post cover image
Table of contents
IntroductionTechnical detailsInfrastructureAttributionConclusionsIndicators of compromise
15 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard