As cited
Copy frozen at (site build).
threat intel
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Kaspersky has identified new components of the Cavern (Cav3rn) command-and-control (C2) framework, a tool deployed by Iranian nation-state actors targeting Israeli entities. The latest variant uses DNS and Google Apps Script to disguise malicious traffic as legitimate communications, enabling the threat actors to avoid detection.
Why it matters: Organizations in Israel and those managing Middle Eastern operations face active targeting by this sophisticated C2 framework; defenders should monitor for DNS anomalies and unusual Google Apps Script execution to identify Cavern activity in their networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Kaspersky has identified new components of the Cavern (Cav3rn) command-and-control (C2) framework, a tool deployed by Iranian nation-state actors targeting Israeli entities. The latest variant uses DNS and Google Apps Script to disguise malicious traffic as legitimate communications, enabling the threat actors to avoid detection.
Why it matters: Organizations in Israel and those managing Middle Eastern operations face active targeting by this sophisticated C2 framework; defenders should monitor for DNS anomalies and unusual Google Apps Script execution to identify Cavern activity in their networks.
- Source published
- First seen by Cybersecurity Tracker