# The Calendar That Reports to Tehran: Inside Iran's Cavern C2 Framework
Somewhere in a compromised Microsoft 365 mailbox, a calendar event is scheduled for May 13, 2050. It will never be attended. The attendee is a machine, and the payload attached isn't a meeting agenda — it's encrypted stolen data, staged in a two-way dead drop that Iranian state hackers have been running against Israeli targets for months.
That's the operational detail at the center of new research from Kaspersky and Group-IB, which together have pulled back the curtain on Cavern — a modular, extensible command-and-control framework attributed with varying confidence to Iranian Ministry of Intelligence and Security (MOIS)-linked actors. What's emerged is a picture of a toolkit that has matured fast, deliberately, and with unusual sophistication in how it blends into traffic that defenders can't simply block.
## What Cavern Actually Is
Cavern, first documented publicly by Check Point Research in early July 2026, isn't a single piece of malware. It's an architecture — an agent plus a plugin system that loads modules for specific mission needs. When you need SQL database enumeration, you load that module. Active Directory reconnaissance, LDAP brute-force, SOCKS5 proxying, WebSocket tunneling — each is a discrete component. That modularity isn't just engineering elegance. It's operational security. Deploy only what you need for a specific intrusion phase, and you limit what a forensic investigator recovers if one component is caught.
Kaspersky has tracked the framework since December 2025 and assessed that Cavern shifted to its current plugin-based architecture in late April 2026. That's a four-month evolution from first detection to second-generation capability — a development cadence that suggests a well-resourced team with a clear roadmap.
The threat cluster behind Cavern is tracked as Cavern Manticore, a group with documented overlaps to MuddyWater and a sub-cluster of OilRig known as Lyceum. Kaspersky has linked Cavern to OilRig (APT34) at low confidence, citing the use of Microsoft-hosted services for C2 — a pattern also seen in RDAT and OilCheck — plus a secondary OAuth token recovery mechanism resembling OilBooster, and compromised regional infrastructure consistent with Solar and Veaty malware. The absence of direct code reuse means this isn't a slam dunk attribution. But the operational fingerprints are hard to ignore.
## DNS as the Traffic Cop
The latest component Kaspersky documented is GoogleService.dll, a communication module that reads a configuration file and performs a DNS A-record query before every transaction. The result of that query determines which channel the malware uses for that specific connection: direct HTTPS to the operator's backend, or a Google Apps Script relay.
That relay mechanism is worth dwelling on. Google Apps Script is a legitimate automation platform used by thousands of organizations daily. Traffic to script.google.com endpoints looks entirely normal. The Cavern module doesn't just route through it blindly — the DNS infrastructure can validate and rotate the Apps Script deployment ID on the fly, meaning operators can swap the relay without redeploying or reconfiguring the implant. If a specific deployment gets flagged or burned, they push a new deployment ID through DNS, and the implant picks it up automatically.
This is channel resilience by design. Defenders who detect the Google relay can't simply block script.google.com without crippling legitimate business operations. The operator can rotate the specific deployment while keeping the channel alive.
## The Calendar Dead Drop
The HOLLOWGRAPH module, detailed in back-to-back reports from Group-IB and Kaspersky, is a different kind of clever. It's a .NET NativeAOT-compiled DLL first caught in the wild on June 7, 2026, and it turns Microsoft 365 calendar functionality into a two-way covert channel.
The mechanism: operators write tasking commands as calendar events in a compromised mailbox. The implant reads those events, executes tasks, and exfiltrates stolen data by creating its own calendar events with encrypted payloads attached as files. Everything is dated to May 13, 2050 — far enough out that it never surfaces in a victim's calendar view or triggers any scheduling notifications.
The authentication side is handled through DNS tunneling. HOLLOWGRAPH uses DNS queries to refresh the Microsoft Entra ID (Azure AD) credentials it needs to authenticate to the Microsoft Graph API, writing updated token values to disk. The Graph API itself is the exfiltration channel — all traffic looks like routine M365 API activity, because functionally, it is.
Group-IB's description of the dead-drop model is precise: "operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached." No custom protocol. No suspicious outbound connection. Just a mailbox exchanging calendar data with Microsoft's own infrastructure.
## Why This Is Harder to Detect Than It Sounds
The convergence of Google and Microsoft legitimate infrastructure as C2 channels reflects a broader strategic calculation by advanced threat actors: the defender's dependency on commercial cloud services is an attack surface. You cannot block Microsoft Graph API traffic in an organization running M365. You cannot block Google Apps Script in an organization using Google Workspace. These aren't obscure third-party services you can selectively firewall — they're the connective tissue of modern operations.
What makes Cavern's implementation specifically dangerous is the separation of concerns. DNS handles channel selection and credential refresh. Google Apps Script handles C2 relay. Microsoft Graph handles exfiltration and tasking. Each layer uses a different legitimate service, making correlation harder and detection signatures narrowly scoped.
---
## HackWire Analysis
The tradecraft in Cavern isn't entirely new — APT groups have been abusing trusted cloud services for C2 since at least 2018, when OilRig used OneDrive for data staging, and Mustang Panda piggybacked on Dropbox. But the implementation here represents a step-change in operational integration. Earlier approaches used cloud storage as a staging area; Cavern uses multiple cloud services as dynamic, rotating, authenticated communication layers with built-in resilience.
What concerns me more than the individual techniques is the pace of development. Kaspersky assessed the plugin architecture emerged in late April 2026. HOLLOWGRAPH was first detected June 7. By mid-August, there are already undocumented components expanding the toolkit. That's a three-month development sprint producing multiple novel C2 mechanisms with operational deployment against live targets. This is not a group experimenting. This is a group with a delivery schedule.
The low-confidence OilRig attribution is also worth watching. Iran's offensive cyber ecosystem has historically operated with some division of labor — MOIS-linked actors (MuddyWater, Lyceum) distinct from IRGC-linked actors (APT33, APT34/OilRig). If Cavern Manticore is genuinely blurring those lines, or if OilRig's tooling is being shared or repurposed across MOIS operations, that's a structural intelligence picture shift, not just a new malware family.
For defenders, the practical upshot is uncomfortable: behavioral detection matters more than signature detection here. Legitimate-looking Microsoft Graph API calls are generating C2 traffic. Legitimate Google Apps Script endpoints are relaying operator commands. The signal is in the anomaly — calendar events dated to 2050 in compromised accounts, DNS queries correlating with M365 API activity spikes, Apps Script deployments accessed from non-human agent patterns. Hunting for those requires telemetry depth and analyst bandwidth that most organizations outside major enterprises simply don't have.
Organizations running M365 should be auditing Graph API application permissions and reviewing service principal activity logs. This is a concrete, actionable step now — before Cavern or a derivative framework reaches targets outside the current Israel-focused campaign geography.
— HackWire Editorial
---
## Related Coverage