Iranian Hackers Use DNS, Google Scripts to Evade Detection
The Cavern C2 framework leverages legitimate services like DNS and Google Apps Script to mask malicious traffic. This technique helps attackers blend in while targeting Israeli entities.
TL;DR
- Iranian state-sponsored hackers are using the Cavern C2 framework in targeted attacks.
- The malware communicates via DNS queries and Google Apps Script to avoid detection.
- Kaspersky discovered new components of the Cavern toolkit active since late 2025.
- Attackers abuse trusted platforms to mimic normal user behavior.
- Organizations should monitor for anomalous use of common collaboration tools.
A recently analyzed campaign by Iranian nation-state actors reveals how advanced persistent threats continue to evolve their tactics to remain undetected. The group, tracked using the Cavern (or Cav3rn) command-and-control framework, has been observed leveraging widely used services such as DNS and Google Apps Script to disguise malicious communications.
Security firm Kaspersky detailed its findings after monitoring this activity since December 2025. Their analysis uncovered previously unknown modules within the Cavern infrastructure, highlighting the group's ability to adapt and maintain stealth during prolonged operations against specific targets in Israel.
Abusing Legitimate Services
- Cavern uses DNS tunneling to send commands and receive data from compromised systems.
- Google Apps Script is abused to host malicious payloads and relay information covertly.
- These methods help the malware evade network-based detection by blending into normal traffic patterns.
- Legitimate cloud services are often whitelisted, making them ideal channels for attacker communication.
Defensive Considerations
- Organizations should implement behavioral analytics to detect unusual usage of collaboration platforms.
- Monitoring outbound DNS query volumes and anomalies can help identify potential C2 activity.
- Restricting access to scripting environments like Google Apps Script may reduce attack surface.
- Threat intelligence on nation-state toolsets like Cavern can improve proactive defense strategies.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.