Project CAV3RN Module Exploits Outlook Calendar for C2 and DNS Records for Recovery

Project CAV3RN Module Exploits Outlook Calendar for C2 and DNS Records for Recovery

A recent discovery by Kaspersky's Global Response Threat Intelligence team, or GReAT, has shed light on a new CAV3RN module that leverages Microsoft's Outlook calendar to facilitate command and control (C2) communications. The module also establishes a backup connection using DNS AAAA records for co

Researchers at Kaspersky's GReAT team have identified a new module within the Project CAV3RN framework that utilizes Microsoft Graph to execute command and control (C2) communications via Outlook calendar events. This module appears to be designed to maintain a low profile, as it utilizes a legitimate service to establish communication with the attackers' command and control server. The attackers may use this module to send and receive sensitive data, including malware, via the Outlook calendar events.

Furthermore, the GReAT team has found that the module also establishes a backup connection using DNS AAAA records for configuration recovery purposes. This means that even if the primary connection is severed, the attackers can recover their configuration and continue operating undetected.

The use of DNS AAAA records for configuration recovery is a relatively new and innovative approach to maintaining persistence in malware operations. This technique allows attackers to maintain a presence on the compromised network even if their primary communication channels are compromised or severed.

Source: Securelist (Kaspersky)