CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4557

As cited

Copy frozen at (site build).

threat intel

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Kaspersky has identified new components of the Cavern (Cav3rn) command-and-control (C2) framework, a tool deployed by Iranian nation-state actors targeting Israeli entities. The latest variant uses DNS and Google Apps Script to disguise malicious traffic as legitimate communications, enabling the threat actors to avoid detection.

Why it matters: Organizations in Israel and those managing Middle Eastern operations face active targeting by this sophisticated C2 framework; defenders should monitor for DNS anomalies and unusual Google Apps Script execution to identify Cavern activity in their networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Kaspersky has identified new components of the Cavern (Cav3rn) command-and-control (C2) framework, a tool deployed by Iranian nation-state actors targeting Israeli entities. The latest variant uses DNS and Google Apps Script to disguise malicious traffic as legitimate communications, enabling the threat actors to avoid detection.

Why it matters: Organizations in Israel and those managing Middle Eastern operations face active targeting by this sophisticated C2 framework; defenders should monitor for DNS anomalies and unusual Google Apps Script execution to identify Cavern activity in their networks.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary