Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators New Project CAV3RN .NET Native AOT communication module

accesslinkssl.com

TLP:CLEAR
Active

Domain

Description

Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

Sightings (0)

No sightings recorded yet

Details

Name / Label
New Project CAV3RN .NET Native AOT communication module
Pattern Type
STIX
Confidence
75%
Valid From
Jul 23, 2026 14:00
Total Sightings
0
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of accesslinkssl.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.