Project CAV3RN is a modular espionage framework used against targets in Israel. This threat operates by distributing and promoting itself through various channels, including email, web, supply chain, messaging apps, forums, and affiliate programs. The framework's are not explicitly stated, but it is described as a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The communication module, a malicious library, is a 64-bit DLL compiled with 8 NativeAOT. It exports several functions, including GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. During initialization, its host (local broker) registers the module's callback and starts CheckAvailability.
After three seconds, the module sends a type-0 frame to a fixed identifier, which the broker returns. The module then learns the broker's name before starting its C2 worker. The framework's local broker discovers and loads DLL components, routes messages between them, and supports runtime upgrades. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The module reads a malicious file from the process's current working directory and generates a seven-character client identifier if it is missing.[/subscribe_to_unlock_form]
Project CAV3RN is a modular espionage framework used against targets in Israel. This threat operates by distributing and promoting itself through various channels, including email, web, supply chain, messaging apps, forums, and affiliate programs. The framework's are not explicitly stated, but it is described as a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The communication module, a malicious library, is a 64-bit DLL compiled with 8 NativeAOT. It exports several functions, including GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. During initialization, its host (local broker) registers the module's callback and starts CheckAvailability.
After three seconds, the module sends a type-0 frame to a fixed identifier, which the broker returns. The module then learns the broker's name before starting its C2 worker. The framework's local broker discovers and loads DLL components, routes messages between them, and supports runtime upgrades. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The module reads a malicious file from the process's current working directory and generates a seven-character client identifier if it is missing.[emaillocker id="1283"]
The configuration file contains various settings, including the DNS domain, Apps Script deployment ID, and polling delay. The framework uses a complex C2 communication module that supports five internal commands: s_version, s_config, s_enLog, s_deLog, and s_write. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The threat is significant as it demonstrates the evolving architecture and C2 capabilities of Project CAV3RN. Its impact on defenders is serious, and its continued use in espionage activities poses a risk to targets in Israel and potentially other regions.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1102 | Web Service | - |
| Command and control | T1571 | Non | Standard Port- |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
The following reports contain further technical details:
[/emaillocker]