Interestana
Home/News/Cavern C2 Uses DNS and Google Apps Script for Stealth
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Cavern C2 Uses DNS and Google Apps Script for Stealth

Cavern C2 Uses DNS and Google Apps Script for Stealth

Cybersecurity researchers have identified new tactics employed by the Cavern command-and-control (C2) framework, utilized by Iranian nation-state actors in attacks targeting Israeli entities. Kaspersky, a Russian cybersecurity firm, reported in December 2025 that its continuous monitoring of this threat activity cluster has uncovered previously undocumented components. These additions enhance the framework's ability to blend into legitimate network traffic, making detection more challenging. The Cavern C2 framework is designed to facilitate communication between compromised systems and the attackers' infrastructure, enabling them to issue commands, exfiltrate data, and maintain persistence on victim networks. The latest findings highlight a sophisticated evolution in the malware's operational methods, moving beyond traditional C2 channels. Specifically, the framework now leverages Domain Name System (DNS) queries and Google Apps Script to establish covert communication pathways. DNS is a fundamental internet protocol that translates human-readable domain names into machine-readable IP addresses. Attackers can manipulate DNS requests and responses to encode malicious data or commands, often disguising them as routine network activity. This technique is known as DNS tunneling. Google Apps Script, a cloud-based scripting language, offers another avenue for stealthy communication. By embedding malicious scripts within seemingly innocuous Google Sheets or other Google Workspace applications, attackers can create a channel that is difficult to distinguish from legitimate user activity. This approach capitalizes on the widespread use of Google's suite of productivity tools in corporate environments. The use of these legitimate services as a C2 channel is a significant development, as it allows the malware to bypass many security controls that are designed to detect and block traffic to known malicious IP addresses or domains. Instead, the traffic appears to be directed towards trusted cloud services, making it harder for security analysts to differentiate between benign and malicious activity. Kaspersky's research indicates that the threat actors behind Cavern are actively refining their tools and techniques to maintain operational security and evade detection by cybersecurity defenses. The ongoing evolution of the Cavern framework underscores the persistent threat posed by nation-state actors and their capacity to adapt to evolving security landscapes. The discovery prompts a need for enhanced network monitoring strategies that can identify subtle anomalies within DNS traffic and cloud application usage, moving beyond signature-based detection methods. The specific Iranian nation-state group responsible for deploying Cavern has not been publicly named by Kaspersky, but the firm's ongoing analysis continues to track their activities and the framework's development. The targeting of Israeli entities suggests a geopolitical motivation behind these cyber operations, aligning with broader patterns of state-sponsored cyber espionage and disruption.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next