CAV3RN, the threat in your calendar

Article by Nacata Security, 21/07/2026

Did you know your work calendar can become a spying channel?

A group of hackers uses calendar events to send hidden commands.

Kaspersky has been tracking this threat since December 2025 and detected that the malware adopted a completely new architecture, far harder to detect.

The group, linked with low confidence to the Iranian threat actor OilRig, targets entities in Israel and uses compromised infrastructure from local companies to avoid raising suspicion.

Image illustrating the core mechanic: a calendar event with encrypted attachments used as a covert command channel.
Calendar as a weapon

The trick is as simple as it is deeply unsettling for anyone.

The malicious module connects to a compromised mailbox belonging to an Israeli law firm. From there, it creates Outlook events scheduled for the year 2050—a date so far in the future that it never appears in normal calendar views. Each event carries an encrypted command for the infected machine, and the attacker’s responses arrive as simple meeting updates. Everything looks like legitimate traffic.

And if that channel fails, it has a plan B.

When the calendar connection stops working, the malware fires off AAAA-type DNS queries, normally used to retrieve internet addresses. But here, those responses contain—fragmented and disguised—the new credentials needed to access the cloud service. The malware reassembles them piece by piece and resumes control as if nothing had happened.

The recovery domain has been active since December 2025 and remains operational.

The DNS infrastructure used for recovery, cloudlanecdn.com, was registered on December 24, 2025, and migrated to attacker-controlled servers in May 2026. The development timeline aligns with the malware’s evolution, signaling an operation planned months in advance.

Image illustrating the broader pattern: multiple legitimate cloud services interconnected, with a hidden channel concealed within normal traffic.
An expanding pattern

This method is not exclusive to this group.

OilRig has spent years using Microsoft services as a command channel: emails, drafts, and now calendar events make up its repertoire.

Abusing legitimate services makes it nearly impossible to distinguish malicious traffic from normal traffic.

At least four malware families attributed to OilRig have used Microsoft infrastructure as a covert command channel.

The pattern repeats and refines itself.

Each version of this malware is harder to detect than the last. The shift to encrypted calendar events set in 2050 is a direct response to the defensive systems that blocked its previous methods, and that has implications that extend well beyond Israel.

The threat remains under active development.

Kaspersky confirms that the CAV3RN framework changed its architecture at least once between December 2025 and May 2026, and tracking is ongoing. Defenders are not chasing a static threat but an adversary that adjusts its tools in real time. The use of legitimate cloud services as a command channel is already an established trend in high-level digital espionage.

The compromised mailbox belongs to a real, innocent company.

This is not infrastructure built from scratch by the attacker. It is the email account of an Israeli law firm that was compromised and turned into a communication bridge without its owners’ knowledge. This makes detection enormously difficult, because the traffic originates from a legitimate account with a clean history and an established reputation.

In-depth image: a compromised law firm's mailbox turned into an espionage bridge, depicted as a professional briefcase from which data escapes without its owner's knowledge.
Mailbox already compromised

Blocking only typical traffic is not sufficient as a defense.

If the control channel uses calendar services your organization already subscribes to, traditional filters will not stop it. Detecting it requires analyzing behavior within those services: events on anomalous dates, encrypted attachments in appointments, or unusual DNS patterns.

Internal monitoring is now essential.

Organizations that rely on cloud productivity tools must review access permissions to their corporate calendars and mailboxes. Unauthorized access to a single email account can turn your entire communications infrastructure into an active espionage channel for months without anyone noticing.

The attacker is already inside the ecosystem.

As long as the framework remains under active development, the risk of new variants is real. Maintaining vigilance over anomalous access to cloud services is the only effective barrier.

What you can do

  • Review which applications have access to your corporate calendar and mailbox.
  • Enable alerts for calendar events with anomalous dates or attachments.
  • Monitor your network’s DNS queries for unusual patterns.

Would you check today who has access to your work calendar?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Threats

Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.

Information meant to help you act and protect yourself before the problem reaches you.



RATING


8.1



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.