Iranian Hackers' Cavern C2 Just Got Smarter at Hiding in Plain Sight

·
Listen to this article~5 min
Iranian Hackers' Cavern C2 Just Got Smarter at Hiding in Plain Sight

Iranian hackers' Cavern C2 framework now uses DNS tunneling and Google Apps Script to hide malicious traffic in plain sight. Kaspersky researchers reveal new components that make this threat harder to detect than ever.

Cybersecurity researchers have been tracking the evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework, a tool used by Iranian nation-state hackers in attacks targeting entities in Israel. The latest findings reveal something that should worry security teams everywhere: this malware is getting much better at blending into legitimate traffic. Russian cybersecurity firm Kaspersky has been monitoring this threat activity cluster since December 2025. Their ongoing investigation has uncovered previously unreported components that expand the framework's capabilities in significant ways. This isn't just a minor update—it's a fundamental shift in how the attackers operate. ### What Makes Cavern Different Now The most striking development is how Cavern now uses DNS and Google Apps Script to disguise its command-and-control communications. Instead of relying on suspicious-looking domains or known malicious infrastructure, the malware can now hide its traffic within services that look completely normal to most security tools. Think about it this way: if you're a security analyst looking at network logs, you're going to flag traffic to a random IP address in a foreign country. But traffic to Google's servers? That's going to pass under the radar almost every time. That's exactly what makes this technique so dangerous. Here's what the researchers found: - **DNS tunneling**: The malware encodes its commands within DNS queries, which are often overlooked by security monitoring systems - **Google Apps Script integration**: The C2 framework can now use Google's legitimate cloud services as a relay point, making malicious traffic indistinguishable from normal business use - **Modular expansion**: New components can be added to the framework, allowing the attackers to adapt their tactics quickly ### Why This Matters for Your Security Posture For security professionals in the United States, this evolution is a wake-up call. Traditional network monitoring that focuses on blocking known bad IP addresses or domains simply won't catch this kind of activity. The attackers have effectively found a way to hide in the noise of everyday internet traffic. The implications are significant. If you're relying solely on signature-based detection or basic network monitoring, you're likely to miss this threat entirely. The attackers have essentially taken the concept of "living off the land" to the next level, using trusted third-party services as their covert communication channel. ### What Security Teams Should Do Now So what can you do to protect your organization? First, you need to understand that this isn't a problem you can solve with a single security tool. It requires a layered approach: - **Monitor DNS queries**: Look for unusual patterns, such as long subdomains or high volumes of DNS traffic to the same domain - **Inspect cloud service usage**: Keep an eye on how Google Workspace APIs and Apps Script are being used across your network - **Implement behavioral analytics**: Focus on detecting anomalies in traffic patterns rather than just matching known signatures Kaspersky's research shows that this threat is ongoing and evolving. The December 2025 discovery was just the beginning—the framework continues to develop, and the researchers expect to find more components in the future. > "The evolution of Cavern represents a broader trend in cyberattacks: threat actors are increasingly leveraging legitimate services to avoid detection," the researchers noted. ### The Bottom Line This isn't just another malware story. It's a reminder that the lines between legitimate and malicious online activity are becoming increasingly blurred. As attackers get more sophisticated, security teams need to evolve their detection strategies just as quickly. The Cavern framework's use of DNS and Google Apps Script is a clear signal that nation-state hackers are investing heavily in stealth. For anyone responsible for protecting sensitive data, understanding these tactics is no longer optional—it's essential.