Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential Recovery

Project CAV3RN / Cavern Manticore (TL-2026-1588), also tracked as Project CAV3RN, is a high-severity malware campaign, first published 2026-07-21. It is attributed to APT34 (Iran) with low confidence, affects Microsoft Microsoft 365 / Exchange Online (Outlook Calendar via, maps to 34 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1588

Threat ID
TL-2026-1588
Also known as
Project CAV3RN, Cav3rn, Cavern, Cavern Manticore
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-21
Last reviewed
2026-07-21
Attribution
APT34
Attribution confidence
LOW
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
legal services, human resources, government administration, itservices, defense
Target regions
israel, Middle East
Detection rules
9
Indicators of compromise
30

Malware and tooling in Project CAV3RN / Cavern Manticore

Malware and tooling: Project CAV3RN / Cavern Manticore

Kaspersky GReAT identified AzureCommunication.dll, a new .NET Native AOT communication module for the modular Project CAV3RN cyberespionage framework, that exchanges commands and results via Outlook calendar events on a compromised Microsoft 365 mailbox (using Microsoft Graph API) and falls back to exfiltrating replacement Entra credentials through DNS AAAA queries to actor-controlled infrastructure when Graph authentication fails. Check Point Research independently tracks the same/related framework as "Cavern Manticore," a modular, triple-compiled (.NET Framework, Mixed-Mode C++/CLI, .NET Native AOT) toolset deployed via SysAid software abuse and DLL sideloading against Israeli law firms, HR companies, IT providers, government, and defense contractors, with low-to-medium confidence attribution to Iran's MOIS and technical overlap with MuddyWater and Lyceum (an OilRig/APT34 subgroup).

How Project CAV3RN / Cavern Manticore works

Project CAV3RN (internally "Cav3rn"/"Cavern") is a modular cyberespionage framework that Kaspersky has tracked since December 2025 and that Check Point Research independently tracks under the name "Cavern Manticore." The framework evolved from a monolithic Cav3rn-era agent using steganographic PNG-based transport and a WebShell command handler into a controller-based architecture (observed by April 2026) built around a persistent controller component, uxtheme.dll (the "Cavern Agent"), which manages an Agent ID, a polling loop, and command routing, and which loads swappable native communication and post-exploitation plugin modules.

Initial access in the Cavern Manticore intrusions leverages abuse of the SysAid IT service-management software's update feature to deliver a DLL sideloading chain: a legitimate loader is abused to load the trojanized uxtheme.dll (Cavern Agent), which in turn loads the native communication module n-HTCommp.dll for HTTPS/WebSocket-based C2 connectivity. Deliberate compilation-format diversity across the .NET Framework (IL-only, symbol-rich), Mixed-Mode C++/CLI, and .NET 8 Native AOT (fully native, metadata-stripped) forms is used as an explicit anti-analysis strategy, forcing defenders to switch reverse-engineering toolchains between modules; per-module AppDomain isolation further limits in-memory artifact recovery, and NativeAOT runtime descriptors hide P/Invoke API imports from standard import-table analysis.

The most recent and most novel module, AzureCommunication.dll, replaces the legacy n-HTCommp.dll HTTP/WebSocket channel with a covert channel built entirely on legitimate Microsoft 365 services. Compiled with .NET Native AOT (single exported function QueryInterface, accepting a null-terminated UTF-16 command string in the form get_;;_<agent-id>_,_<legacy-url> or send_;;_<agent-id>_,_<legacy-url>_,_<result>), the module stores its configuration in a file named logAzure.txt containing a hardcoded Microsoft Entra tenant ID, application (client) credentials, the target mailbox address, a DNS bootstrap hostname, and an embedded RSA key pair. Using the Microsoft Graph API against a compromised Israeli law-firm Microsoft 365 mailbox, the module creates and reads calendar events that function as an asynchronous C2 dead-drop: all events are scheduled inside a single fixed one-hour window (2050-05-13 22:00-23:00 UTC) far in the future so they never surface in a normal calendar view. Event subjects encode message type and agent identity: "Event ID: <agent-id>" carries operator-to-agent commands, "Boss update ID: <agent-id>1500" is an agent heartbeat, and "Boss Report ID: <agent-id>1500" carries agent-to-operator results. Command payloads embedded in event bodies are protected with RSA-OAEP-SHA256 (256-byte key-transport block) wrapping an AES-256-GCM-encrypted body; the implant decrypts using its embedded RSA private key and re-encrypts results before writing its own calendar event.

When Microsoft Graph authentication fails (e.g., revoked application credentials or blocked tenant), AzureCommunication.dll falls back to a DNS AAAA-based configuration-recovery channel against the actor-registered domain cloudlanecdn[.]com (registered 2025-12-24; delegated to dedicated nameservers ns1-ns4.cloudlanecdn[.]com on 2026-05-02). Agent IDs are converted to uppercase hexadecimal (e.g., SFmLgQZ -> 53466D4C67515A) and embedded into subdomain labels. A length query of the form d.<hex-agent-id>.<field-index>.p.<host> returns the size of a requested configuration field (TenantId, ClientId, ClientSecret, or UserEmail) encoded in bytes 2-3 of the returned AAAA (IPv6) address; the module then issues sequential data queries of the form d.<hex-agent-id>.<field-index>.<offset>.q.<host>, each returning a 14-byte chunk of the field value embedded in the AAAA response bytes, until the full value is reassembled. A sentinel response of 2001:4998:44:3507::8000 signals that no data is currently available for that query, allowing the implant to retry. This mechanism lets the operators silently rotate compromised Entra application credentials for the primary channel without needing a working authenticated session.

Check Point's overlapping "Cavern Manticore" reporting documents a broader plugin family alongside the Cavern Agent and communication modules: mhm.dll (file-manager, including DPAPI blob decryption), db.dll (SQL Server/database browsing and querying), ode.dll (LDAP/Active Directory reconnaissance and brute-forcing), n-ten.dll (network reconnaissance, port scanning, SMB brute-forcing), and n-sws.dll (SOCKS5 proxying and WebSocket protocol tunneling for pivoting into internal networks). The framework implements a command-ID taxonomy of roughly 60 numbered operator commands spanning agent self-management, host/token/DPAPI info gathering, SQL operations, file/directory manipulation, LDAP/AD enumeration and brute force, process/registry/service management (present in code but not deployed in the current modular build), archive/compression, network reconnaissance (DNS, interfaces, ping, ARP, port scan), SMB operations, and local/domain user and group enumeration -- consistent with an operational focus on credential harvesting, internal reconnaissance, and lateral movement following an initial IT-provider or professional-services foothold. Debug artifacts (a PDB path referencing a developer alias, English-language error strings with informal phrasing and typos) indicate hands-on human development, in some cases alongside apparent AI-assisted boilerplate.

Victimology centers on Israeli organizations -- specifically law firms and human-resources companies in the Kaspersky-documented AzureCommunication.dll intrusion, and IT service providers, government bodies, and defense contractors in the broader Cavern Manticore reporting, consistent with a supply-chain strategy of compromising IT/MSP infrastructure as a first-hop pivot into higher-value downstream government and defense targets; related reporting also references a wider Middle East footprint (aviation, energy, and public-sector targeting extending to Egypt and the UAE). Attribution to Iran's Ministry of Intelligence and Security (MOIS)-linked activity is assessed at low-to-medium confidence, based on: use of trusted Microsoft-hosted services for C2 (paralleling known OilRig/APT34 tradecraft such as RDAT's use of Exchange Web Services and OilCheck's use of Microsoft Graph), a DNS-based secondary/fallback recovery channel for configuration data (paralleling OilBooster's HTTP-based token-recovery mechanism and OilRig's long history of DNS tunneling), targeting overlap and TTP overlap with MuddyWater and Lyceum (assessed as an OilRig/APT34 subgroup), and the abuse of compromised regional (Israeli) infrastructure consistent with prior OilRig-linked Solar and Whisper/Veaty malware activity. No CVE or exploited software vulnerability underlies this campaign; the SysAid abuse described in overlapping reporting is a feature/update-mechanism abuse rather than a documented CVE, and the framework's initial access relies on supply-chain/IT-provider trust abuse rather than a specific unpatched flaw.

MITRE ATT&CK techniques used in TL-2026-1588

Collection

T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1071.004 DNS; T1090.002 External Proxy; T1102 Web Service; T1572 Protocol Tunneling; T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1482 Domain Trust Discovery; T1538 Cloud Service Dashboard

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Lateral Movement

T1021.002 SMB/Windows Admin Shares; T1021.006 Windows Remote Management

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1027.004 Compile After Delivery; T1140 Deobfuscate/Decode Files or Information

Credential Access

T1110 Brute Force; T1552.001 Credentials In Files; T1555.004 Windows Credential Manager

Initial Access

T1199 Trusted Relationship

Persistence

T1547.013 XDG Autostart Entries

Execution

T1569.002 Service Execution

stealth

T1574.001 DLL

Affected products and versions in Project CAV3RN / Cavern Manticore

  • Microsoft — Microsoft 365 / Exchange Online (Outlook Calendar via Microsoft Graph API)
    Vulnerable versions: cloud service - abused via compromised application credentials, not a code vulnerability
  • SysAid — SysAid IT Service Management (update mechanism abused for DLL sideloading in overlapping Cavern Manticore reporting)
    Vulnerable versions: on-premise deployments with update-mechanism abuse observed

Remediation for Project CAV3RN / Cavern Manticore

Immediate actions

  • Block network communication to cloudlanecdn[.]com, ns1-ns4.cloudlanecdn[.]com, and hospitalinstallation[.]com and its subdomains at DNS resolvers and perimeter firewalls
  • Block outbound traffic to 216.126.237.197 and 144.172.108.205 (AS14956 RouterHosting LLC)
  • Audit Microsoft Entra ID app registrations and OAuth application consents granted to the tenant hosting the affected mailbox; revoke and rotate any unrecognized or over-privileged application credentials (client secrets/certificates)
  • Review Microsoft 365 mailbox audit logs (Unified Audit Log / MailItemsAccessed, calendar CreateEvent/UpdateEvent) for anomalous Graph API calendar activity, especially events scheduled far in the future or outside normal business calendar patterns
  • Hunt for the named files/hashes (AzureCommunication.dll, uxtheme.dll, n-HTCommp.dll, mhm.dll, db.dll, ode.dll, n-ten.dll, n-sws.dll, logAzure.txt, config.txt, NewProject.dll) and associated mutexes (MYMUTEX123HELLP, MYMUTEX123HELLP02, MYMUTEX123HELLP04) across endpoints
  • If SysAid is deployed, audit and restrict its update mechanism and validate the integrity of delivered updates/DLLs; monitor for DLL sideloading against legitimate SysAid or WinDirStat binaries
  • Alert on anomalous high-volume or sequential AAAA (IPv6) DNS queries to non-corporate domains, especially queries with structured/hex-encoded subdomain labels

Workarounds

  • Disable or tightly restrict SysAid auto-update functionality until integrity of the update chain can be validated
  • Restrict or monitor Microsoft Graph calendar API access for the affected mailbox/tenant pending full incident response

Longer-term hardening

  • Deploy conditional access policies and continuous access evaluation for Microsoft Graph API application permissions, especially Calendars.ReadWrite and Mail scopes
  • Implement DNS query logging and analytics (e.g., passive DNS, RPZ) capable of detecting DNS tunneling/exfiltration patterns over AAAA records
  • Enforce least-privilege and time-bound Entra application credentials; rotate application secrets on a defined cadence and monitor for out-of-band credential recovery patterns
  • Segment and monitor IT/MSP-provider network access into downstream government/defense-sector environments given the supply-chain pivot pattern observed
  • Deploy EDR capable of detecting AppDomain-isolated .NET Native AOT module loading and unusual P/Invoke behavior masked by stripped import tables

Timeline of Project CAV3RN / Cavern Manticore

  • Kaspersky GReAT begins tracking the Cav3rn threat cluster following identification of the monolithic Cav3rn-era agent using steganographic PNG transport and a WebShell command handler.
  • Actor-controlled domain cloudlanecdn[.]com registered, later used for DNS AAAA-based credential recovery channel.
  • Framework observed shifting from a three-component monolithic system to a controller-based modular architecture (uxtheme.dll controller with swappable plugins).
  • cloudlanecdn[.]com delegated from vendor-managed to custom nameservers ns1-ns3.cloudlanecdn[.]com in preparation for the DNS AAAA recovery channel.
  • AzureCommunication.dll compile timestamp observed, marking deployment of the new Microsoft Graph/Outlook-calendar C2 module replacing the legacy n-HTCommp.dll HTTP/WebSocket channel.
  • Fourth nameserver ns4.cloudlanecdn[.]com first observed in passive DNS, completing the dedicated nameserver set for the DNS AAAA credential-recovery channel.
  • Kaspersky GReAT publishes extensive internal research on the Project CAV3RN framework's targeting of Israeli entities, ahead of the later public Securelist writeup.
  • Check Point Research publishes overlapping analysis of the same/related framework under the name "Cavern Manticore," documenting SysAid-based initial access, DLL sideloading, and additional post-exploitation modules (mhm.dll, db.dll, ode.dll, n-ten.dll, n-sws.dll); The Hacker News reports on the campaign the same week.
  • Kaspersky Securelist publishes "Project CAV3RN: cyberespionage framework using Outlook and DNS," detailing the AzureCommunication.dll module's Outlook-calendar C2 and DNS AAAA credential-recovery mechanism against a compromised Israeli law-firm Microsoft 365 mailbox.

Sources cited for Project CAV3RN / Cavern Manticore

Threats related to Project CAV3RN / Cavern Manticore

Detection coverage for TL-2026-1588

As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1588 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1588

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats