Iranian Hackers Found a Sneaky Way to Hide Their Command Server in Plain Sight
Robert Moore ·
Listen to this article~5 min
Iranian hackers behind the Cavern C2 framework are hiding malicious traffic inside DNS queries and Google Apps Script. Kaspersky reveals how this stealthy approach evades detection and what it means for security teams.
Cybersecurity researchers have been tracking the evolution of a nasty piece of malware called Cavern (also known as Cav3rn), and what they've found is both clever and concerning. This command-and-control (C2) framework, linked to Iranian nation-state hackers, has been actively targeting organizations in Israel. But here's the twist: the attackers aren't using flashy new exploits or zero-day vulnerabilities. Instead, they're hiding their malicious traffic inside everyday services that most security tools automatically trust.
### The Art of Blending In
The whole idea behind a command-and-control server is to let hackers remotely control infected machines. Traditionally, these servers use dedicated IP addresses or domains that security teams can quickly block. But Cavern takes a different approach. It uses DNS queries and Google Apps Script to communicate with infected systems, making the malicious traffic look almost identical to normal internet activity.
Think about it this way. If you're a security guard checking ID badges at a building entrance, you're going to stop someone wearing a ski mask. But if someone walks in wearing the same uniform as everyone else, you're probably not going to give them a second look. That's exactly what Cavern is doing. It's wearing the uniform of legitimate web traffic.
### What Kaspersky Found
Russian cybersecurity firm Kaspersky has been monitoring this threat cluster since December 2025. Their ongoing investigation has uncovered previously unreported components that expand the framework's capabilities. The researchers noted that Cavern's operators are constantly refining their tools, adding new features, and finding fresh ways to evade detection.
One of the most interesting discoveries is how the malware uses Google's own infrastructure against us. Google Apps Script is a legitimate cloud-based scripting platform used by millions of businesses. By abusing this service, Cavern's traffic gets a free pass through many security filters because the domains and certificates are already whitelisted.
### Why This Matters for Security Teams
This isn't just another malware report. It's a wake-up call that traditional network monitoring might not be enough anymore. Here's what makes Cavern particularly dangerous:
- It uses standard DNS protocols, which are rarely blocked or heavily inspected
- It leverages Google's trusted infrastructure, bypassing many reputation-based filters
- It can rotate through multiple communication channels, making it harder to disrupt
- The C2 framework is modular, allowing attackers to add new capabilities on the fly
### The Bigger Picture
Nation-state actors have always been ahead of the curve when it comes to stealth. But this move toward hiding inside legitimate cloud services represents a significant shift. It's no longer enough to block known bad IP addresses or domains. Security teams need to look at behavior, not just reputation.
For businesses in the United States and around the world, this is a reminder that the threat landscape keeps evolving. Iranian hacking groups have historically focused on Middle Eastern targets, but the techniques they develop often get shared or copied by other threat actors. The methods Cavern uses today could easily show up in ransomware attacks against American companies tomorrow.
### What You Can Do
If you're responsible for network security, here are a few practical steps to consider:
- Monitor DNS queries for unusual patterns, especially long or encoded subdomains
- Pay attention to Google Apps Script executions that don't match your organization's normal usage
- Implement behavioral analytics rather than relying solely on signature-based detection
- Keep your threat intelligence feeds updated with the latest indicators of compromise
### The Takeaway
The Cavern framework is a perfect example of how modern cybercriminals think outside the box. They're not trying to break through your front door anymore. They're finding ways to walk in through the loading dock, wearing the same uniform as your own employees. The only way to catch them is to watch what people are doing, not just who they are.
Kaspersky's research highlights the importance of continuous monitoring and adaptation. The threat landscape is changing fast, and the tools we used yesterday might not catch the attacks of tomorrow. Staying informed and staying vigilant is no longer optional. It's the price of doing business in a connected world.