Cavern C2 Framework Adds DNS and Google Apps Script Channels in Ongoing Iranian Campaign Targeting Israel
What Happened
Kaspersky researchers report continued evolution of the Cavern (also tracked as Cav3rn) command-and-control framework, used by Iranian nation-state threat actors in attacks against entities in Israel. According to Kaspersky, ongoing monitoring of this activity cluster since December 2025 has uncovered previously unreported components that expand the framework's capabilities, including use of DNS and Google Apps Script to blend C2 traffic into legitimate-looking network activity. Details on the newly discovered components and the full scope of the campaign are still emerging.
Why It Matters for Defenders
Blending C2 communications into DNS traffic and trusted cloud services like Google Apps Script is a well-established evasion technique — both channels are commonly allow-listed or under-scrutinized in enterprise environments, making detection harder with traditional network monitoring. Organizations in Israel, and potentially other entities targeted by Iranian state-nexus actors, should treat this as an active, evolving threat. The use of legitimate infrastructure (Google's platform) as a C2 conduit also complicates attribution and blocking, since defenders can't simply blacklist the underlying service.
What Defenders Should Watch For
- Anomalous or high-volume DNS query patterns, especially to newly registered or low-reputation domains, unusual record types, or irregular query timing consistent with DNS tunneling.
- Outbound connections to
script.google.comor other Google Apps Script endpoints from hosts that don't normally use them, particularly paired with scripted/automated request patterns. - Correlating DNS and cloud-service telemetry together rather than in isolation, since this technique is designed to look benign in either data source alone.
- Reviewing threat intelligence feeds for indicators associated with Cavern/Cav3rn as they are published, and monitoring for follow-on reporting on the newly discovered components.
- General hardening against Iranian APT tradecraft targeting the region, including phishing-resistant authentication and egress monitoring for command-and-control beaconing.
Developing Story
This is net-new intelligence based on Kaspersky's ongoing monitoring, and further technical details on the specific components and indicators had not been fully disclosed at the time of reporting. We will continue to track this story as more information becomes available. Read the original report at The Hacker News.