top of page
ALL POSTS
Project CAV3RN Abuses Outlook Calendar Events for C2 Communication and Covert Israeli Surveillance
Key Findings Project CAV3RN, an espionage framework targeting Israeli organizations, now uses Outlook calendar events as a command-and-control channel accessed through Microsoft Graph The new AzureCommunication.dll module hides commands in calendar events dated to 2050 to avoid detection; operators use encrypted attachments for payload delivery If Microsoft Graph fails, the malware retrieves backup credentials through DNS AAAA records, using the recovery domain cloudlanecdn[.
Jul 213 min read
Update: emldump.py Version 0.0.17
Background The emldump.py script is a powerful tool used by security analysts and incident responders to extract and analyze data from Microsoft Outlook email archives. This update focuses on enhancing the functionality of the "--yarastrings" option, which allows users to search for specific Yara signatures within the email data. Key Findings The update to emldump.py version 0.0.16 includes fixes and improvements to the "--yarastrings" option. The provided MD5 and SHA256 hash
Mar 91 min read
bottom of page
