Cavern C2 Framework Leverages DNS and Google Apps Script for Evasion
The Cavern C2 framework employs DNS A-record responses to dynamically select between direct HTTPS and Google Apps Script relays, enabling it to blend with legitimate traffic. Its modular architecture and use of trusted services like Google Apps Script complicate detection and highlight evolving evasion techniques in cyber espionage campaigns.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the
*** END OF TRANSMISSION ***