Threat Advisory

Project CAV3RN Framework Uses DNS A-Record Responses for Complex C2 Communication

Threat: Malware
Targeted Region: Israel
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Project CAV3RN is a modular espionage framework used against targets in Israel. This threat operates by distributing and promoting itself through various channels, including email, web, supply chain, messaging apps, forums, and affiliate programs. The framework's are not explicitly stated, but it is described as a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The communication module, a malicious library, is a 64-bit DLL compiled with 8 NativeAOT. It exports several functions, including GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. During initialization, its host (local broker) registers the module's callback and starts CheckAvailability.

After three seconds, the module sends a type-0 frame to a fixed identifier, which the broker returns. The module then learns the broker's name before starting its C2 worker. The framework's local broker discovers and loads DLL components, routes messages between them, and supports runtime upgrades. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The module reads a malicious file from the process's current working directory and generates a seven-character client identifier if it is missing.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Project CAV3RN is a modular espionage framework used against targets in Israel. This threat operates by distributing and promoting itself through various channels, including email, web, supply chain, messaging apps, forums, and affiliate programs. The framework's are not explicitly stated, but it is described as a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The communication module, a malicious library, is a 64-bit DLL compiled with 8 NativeAOT. It exports several functions, including GroupByCategory, CheckAvailability, IsPrimeNumber, and OrderByDate. During initialization, its host (local broker) registers the module's callback and starts CheckAvailability.

After three seconds, the module sends a type-0 frame to a fixed identifier, which the broker returns. The module then learns the broker's name before starting its C2 worker. The framework's local broker discovers and loads DLL components, routes messages between them, and supports runtime upgrades. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The module reads a malicious file from the process's current working directory and generates a seven-character client identifier if it is missing.[emaillocker id="1283"]

The configuration file contains various settings, including the DNS domain, Apps Script deployment ID, and polling delay. The framework uses a complex C2 communication module that supports five internal commands: s_version, s_config, s_enLog, s_deLog, and s_write. It also enables diagnostic logging at the Debug level and disables it at the Fatal level. The threat is significant as it demonstrates the evolving architecture and C2 capabilities of Project CAV3RN. Its impact on defenders is serious, and its continued use in espionage activities poses a risk to targets in Israel and potentially other regions.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1102 Web Service -
Command and control T1571 Non Standard Port-
Command and control T1573.001 Encrypted Channel Symmetric Cryptography

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Anti-Static Analysis E1027 Obfuscated Files or Information

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu