Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

August 23, 2026

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

August 22, 2026

VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

August 22, 2026
Facebook X (Twitter) Instagram
Sunday, August 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
News

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Team-CWDBy Team-CWDAugust 22, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.

Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the toolkit’s communication capabilities.

“The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction,” Kaspersky said in an analysis. “The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel.”

Cavern, first publicly documented by Check Point Research in early July 2026, consists of multiple moving parts, including an Agent and an assortment of modules, that work in tandem to enable mission-specific post-exploitation functionality, while minimizing forensic visibility and ensuring persistent access.

The modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling. The use of Cavern C2 has been linked to Cavern Manticore, a hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) that shares overlaps with MuddyWater and an OilRig sub-group known as Lyceum.

Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels. The malware, in particular, abuses the Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.

“Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached,” Group-IB noted. “To avoid catching the mailbox owner’s attention, every event is dated far into the future — 13 May 2050 — with payloads attached as files to the event.”

In tandem, the malware employs DNS tunneling as a way to refresh the Microsoft Entra ID (Azure AD) credentials used to authenticate to the Graph API and write the updated values to a text file on disk. A .NET NativeAOT-compiled DLL, HOLLOWGRAPH, was first detected in the wild on June 7, 2026.

Cavern’s shift to a modular, extensible architecture using a plugin-based system is assessed to have taken place in late April 2026, per Kaspersky, which has since linked it to OilRig (aka APT34) with low confidence, citing the following indicators despite no direct code reuse or infrastructure overlap –

  • Use of Microsoft-hosted services for C2 (e.g., RDAT, OilCheck)
  • Presence of secondary recovery mechanism to obtain replacement OAuth refresh tokens, as observed in OilBooster
  • Use of compromised infrastructure belonging to entities in regions it targets, as observed in Solar and Veaty malware

The latest findings from Kaspersky are a new communication module, GoogleService.dll, which reads a configuration file from disk (“conf.json”) and performs a DNS A-record query to opt for either a direct HTTPS or a Google Apps Script relay for each transaction.

When the Google mode is selected, the module sends requests to the Apps Script deployment, which then forwards them to the threat actor-controlled backend. If Direct HTTPS is chosen by DNS, it contacts the configured address without using the relay.

The cybersecurity vendor said it also discovered an inter-component broker (“rnp.dll”) that functions as the framework’s local bridge, which discovers and loads DLL components, routes messages between them, and supports runtime upgrades. Although the primary domain linked to the activity (“studiotikva[.]com”) was first registered in February 2024, the domain is said to have expired in February 2026, only for it to be re-registered three months later.

The development is a sign of ongoing evolution of the Cavern framework, while relying on legitimate services to evade conventional perimeter defenses.

“By abusing legitimate services — previously Outlook calendar events and now Google Apps Script — the framework blends its C2 traffic with normal network activity, complicating network-based detection,” Kaspersky said. “Given its development pace, modular design, and operational tempo, we assess that Cav3rn will likely continue to expand.”

APT42 Resurfaces with TAMECAT

The disclosure comes as DarkAtlas detailed APT42’s use of TAMECAT in spear-phishing attacks targeting individuals associated with the nuclear energy sector as recently as April and May 2026 via LNK files masquerading as PDF documents.

“The social-engineering theme used podcast and interview invitations, continuing the group’s preference for credible professional engagement before malware delivery,” DarkAtlas said.

The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.

The Iranian hacking group has also been observed using generative artificial intelligence (AI) as a way to accelerate operations, including developing specialized tooling, researching exploitation techniques, language translation, and identifying official email addresses, and investigating entities of interest.

“APT42 remains an intelligence-collection threat whose advantage comes from patient human targeting, now accelerated by AI and supported by more resilient malware when needed,” DarkAtlas said.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleVMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Next Article Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Team-CWD
  • Website

Related Posts

News

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

August 23, 2026
News

VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

August 22, 2026
News

How MCP Servers Can Expose Enterprise Secrets

August 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Your information is on the dark web. What happens next?

January 13, 2026

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.