Dormant Medium impact Espionage Checked 4d ago

Spy malware hides in hacked Microsoft 365 calendars

Kaspersky's continued tracking through mid-August found that the Cavern (Cav3rn) spying toolkit, used by the Iran-linked group Cavern Manticore, added a new communication module. It can choose between a direct web connection and Google Apps Script for each exchange, and it can use web address lookups to replace blocked Google connection details. This extends the toolkit that used HOLLOWGRAPH to hide commands and stolen files in Microsoft 365 calendar events dated 2050. Cavern was first publicly documented by Check Point Research in July 2026. No new public reporting has surfaced since mid-August 2026.

Started
Jul 5, 2026
Latest activity
Aug 17, 2026
Attributed to
Cavern Manticore (Iran MOIS-linked); possible OilRig (APT34) tie, low confidenceSuspected
Where
Israel
Sectors
Multiple sectors
Scale
At least 12 infected computers were identified by Group-IB

Current status

No new credible reporting on Cavern Manticore or the CAV3RN toolkit has appeared since The Hacker News' August 17, 2026 writeup; searches on 2026-09-06 for Cavern Manticore, CAV3RN, HOLLOWGRAPH, studiotikva.com, and Lyceum/OilRig calendar malware turned up nothing newer.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

No new source has strengthened or changed the low-confidence OilRig/Lyceum overlap reported by Kaspersky on August 17, 2026.

Impact

The malware can receive commands and send sensitive information through normal-looking Microsoft or Google cloud traffic. It can switch communication routes and update its Google connection details, making infections harder to spot and block. Kaspersky says the toolkit is under active, fast-paced development and expects it to keep expanding.

What to do

IT teams should check Microsoft 365 mailboxes for calendar events dated far in the future, such as the year 2050. They should also investigate encrypted calendar attachments, unusual OAuth app grants, unexpected traffic to Google Apps Script, and unusual DNS lookups. Connections to studiotikva.com or api.studiotikva.com should be blocked and investigated.

Timeline

  1. Sep 7, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 17, 2026

    The Hacker News published a fuller Kaspersky-based writeup naming the operators Cavern Manticore, an Iran MOIS-linked group overlapping with MuddyWater and an OilRig sub-group called Lyceum, and detailed the new GoogleService.dll module and an inter-component broker (rnp.dll). The report noted the studiotikva.com C2 domain was registered in 2024, expired in February 2026, and was re-registered about three months later, and said Kaspersky assesses the toolkit will likely keep expanding.

    Activethehackernews.com
  3. Aug 12, 2026

    New reports on Kaspersky's research said continued tracking in early August found new CAV3RN components that use Google Apps Script, direct web connections, and web address lookups to keep communicating with infected systems.

    Activecyberpress.org
  4. Aug 11, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  5. Jul 21, 2026

    Kaspersky published a deeper technical writeup of the malware's newest module, showing it can fall back to ordinary DNS lookups for fresh instructions if its hidden calendar channel is blocked, and said it has low-confidence evidence tying the campaign to the Iranian group OilRig (APT34), including a compromised email account at an Israeli law firm used to run the scheme.

    Activesecurelist.com
  6. Jul 21, 2026

    SecurityWeek and Redmondmag reported the malware as part of a larger toolkit using the calendar as a two-way dead drop, with no resolution announced.

    Activesecurityweek.com
  7. Jul 20, 2026

    Group-IB published its own HOLLOWGRAPH research, reporting at least 12 infected systems and a high-confidence link to the Cavern backdoor framework.

    Activethehackernews.com
  8. Jul 13, 2026

    Kaspersky linked the calendar-abuse technique to the Project CAV3RN framework and highly targeted spying against Israeli organizations.

    Activecybersecuritynews.com
  9. Jul 5, 2026

    Cyber Security News first reported the HOLLOWGRAPH malware abusing Microsoft 365 calendars as a hidden two-way channel.

    Emergingcybersecuritynews.com

Sources

Related reports