Spy malware hides in hacked Microsoft 365 calendars
Kaspersky's continued tracking through mid-August found that the Cavern (Cav3rn) spying toolkit, used by the Iran-linked group Cavern Manticore, added a new communication module. It can choose between a direct web connection and Google Apps Script for each exchange, and it can use web address lookups to replace blocked Google connection details. This extends the toolkit that used HOLLOWGRAPH to hide commands and stolen files in Microsoft 365 calendar events dated 2050. Cavern was first publicly documented by Check Point Research in July 2026. No new public reporting has surfaced since mid-August 2026.
- Started
- Jul 5, 2026
- Latest activity
- Aug 17, 2026
- Attributed to
- Cavern Manticore (Iran MOIS-linked); possible OilRig (APT34) tie, low confidenceSuspected
- Where
- Israel
- Sectors
- Multiple sectors
- Scale
- At least 12 infected computers were identified by Group-IB
Current status
No new credible reporting on Cavern Manticore or the CAV3RN toolkit has appeared since The Hacker News' August 17, 2026 writeup; searches on 2026-09-06 for Cavern Manticore, CAV3RN, HOLLOWGRAPH, studiotikva.com, and Lyceum/OilRig calendar malware turned up nothing newer.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
No new source has strengthened or changed the low-confidence OilRig/Lyceum overlap reported by Kaspersky on August 17, 2026.
Impact
The malware can receive commands and send sensitive information through normal-looking Microsoft or Google cloud traffic. It can switch communication routes and update its Google connection details, making infections harder to spot and block. Kaspersky says the toolkit is under active, fast-paced development and expects it to keep expanding.
What to do
IT teams should check Microsoft 365 mailboxes for calendar events dated far in the future, such as the year 2050. They should also investigate encrypted calendar attachments, unusual OAuth app grants, unexpected traffic to Google Apps Script, and unusual DNS lookups. Connections to studiotikva.com or api.studiotikva.com should be blocked and investigated.
Timeline
-
Sep 7, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 17, 2026
The Hacker News published a fuller Kaspersky-based writeup naming the operators Cavern Manticore, an Iran MOIS-linked group overlapping with MuddyWater and an OilRig sub-group called Lyceum, and detailed the new GoogleService.dll module and an inter-component broker (rnp.dll). The report noted the studiotikva.com C2 domain was registered in 2024, expired in February 2026, and was re-registered about three months later, and said Kaspersky assesses the toolkit will likely keep expanding.
Activethehackernews.com -
Aug 12, 2026
New reports on Kaspersky's research said continued tracking in early August found new CAV3RN components that use Google Apps Script, direct web connections, and web address lookups to keep communicating with infected systems.
Activecyberpress.org -
Aug 11, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 21, 2026
Kaspersky published a deeper technical writeup of the malware's newest module, showing it can fall back to ordinary DNS lookups for fresh instructions if its hidden calendar channel is blocked, and said it has low-confidence evidence tying the campaign to the Iranian group OilRig (APT34), including a compromised email account at an Israeli law firm used to run the scheme.
Activesecurelist.com -
Jul 21, 2026
SecurityWeek and Redmondmag reported the malware as part of a larger toolkit using the calendar as a two-way dead drop, with no resolution announced.
Activesecurityweek.com -
Jul 20, 2026
Group-IB published its own HOLLOWGRAPH research, reporting at least 12 infected systems and a high-confidence link to the Cavern backdoor framework.
Activethehackernews.com -
Jul 13, 2026
Kaspersky linked the calendar-abuse technique to the Project CAV3RN framework and highly targeted spying against Israeli organizations.
Activecybersecuritynews.com -
Jul 5, 2026
Cyber Security News first reported the HOLLOWGRAPH malware abusing Microsoft 365 calendars as a hidden two-way channel.
Emergingcybersecuritynews.com
Sources
- HollowGraph malware hides in Microsoft 365 calendar invites Cyber Security News Jul 5, 2026
- Outlook malware hides commands in fake 2050 calendar events Cyber Security News Jul 13, 2026
- Microsoft 365 calendar events hide spyware commands VPNCentral Jul 17, 2026
- Microsoft 365 mailboxes hijacked for spyware BleepingComputer Jul 20, 2026
- Microsoft 365 accounts used to hide spyware commands TheHackerNews Jul 20, 2026
- HollowGraph malware hides in Microsoft 365 calendars Infosecurity Magazine Jul 20, 2026
- Microsoft 365 accounts hijacked to send spy malware SecurityWeek Jul 21, 2026
- HOLLOWGRAPH malware turns Microsoft 365 calendars into covert attack channels Redmondmag Jul 21, 2026
- New Project CAV3RN .NET Native AOT communication module Securelist (Kaspersky) Jul 21, 2026
- Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Check Point Research Jul 6, 2026
- Malware Turns Microsoft 365 Calendar Into Covert Attack Vector Campus Technology Aug 4, 2026
- HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Channels Group-IB Jul 20, 2026
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection Kaspersky Securelist Aug 11, 2026
- Kaspersky discovered new malicious tools used in attacks on Israeli organizations Kaspersky Aug 11, 2026
- CAV3RN Hides Cyberespionage C2 Behind Google Apps Script and Lets DNS Pick the Route Cyber Press Aug 12, 2026
- Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks GBHackers Aug 12, 2026
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Hacker News Aug 17, 2026
Related reports
- Microsoft 365 accounts hijacked to send spy malware Jul 21, 2026
- Microsoft 365 accounts used to hide spyware commands Jul 20, 2026
- Microsoft 365 calendar malware steals data Jul 20, 2026
- Microsoft 365 mailboxes hijacked for spyware Jul 20, 2026
- HOLLOWGRAPH malware hides in Microsoft 365 calendars Jul 17, 2026
- Microsoft 365 calendar events hide spyware commands Jul 17, 2026
- Outlook malware hides commands in fake 2050 calendar events Jul 13, 2026
- HollowGraph malware hides in Microsoft 365 calendar invites Jul 5, 2026