CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Cavern C2 Framework Evolves with DNS and Google Apps Script to Evade Detection

August 17, 2026

Cybersecurity researchers have uncovered new components in the Cavern (aka Cav3rn) command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting entities in Israel. Kaspersky’s ongoing monitoring since December 2025 revealed a complex C2 module that leverages DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The same DNS infrastructure can validate and replace the relay deployment ID, allowing operators to rotate the Google channel.

Cavern, first documented by Check Point Research in July 2026, consists of an Agent and multiple modules enabling file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling. The framework is linked to Cavern Manticore, a hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS), with overlaps to MuddyWater and OilRig sub-group Lyceum.

Recent reports from Group-IB and Kaspersky detailed HOLLOWGRAPH, a module that abuses Microsoft Graph API to turn Microsoft 365 calendars into covert C2 channels. It uses calendar events as a two-way dead-drop, with events dated far into the future (13 May 2050) to avoid detection. DNS tunneling refreshes Microsoft Entra ID credentials used for Graph API authentication.

Kaspersky also discovered GoogleService.dll, a new communication module that reads a configuration file and performs DNS A-record queries to select between direct HTTPS or Google Apps Script relay. An inter-component broker (rnp.dll) functions as a local bridge, discovering and loading DLL components, routing messages, and supporting runtime upgrades. The primary domain ‘studiotikva[.]com’ was re-registered in May 2026 after expiring in February 2026.

In related news, DarkAtlas detailed APT42’s use of TAMECAT in spear-phishing attacks targeting the nuclear energy sector. TAMECAT is a modular surveillance framework supporting enumeration, command execution, credential collection, and fallback C2 mechanisms. APT42 has also been observed using generative AI to accelerate operations, including tool development and target research.

Attack groups: Cavern Manticore, MuddyWater, OilRig, Lyceum, APT42

Malware: Cavern, HOLLOWGRAPH, TAMECAT, OilBooster, Solar, Veaty

Companies: Kaspersky, Group-IB, Check Point Research, DarkAtlas, Microsoft

Products: Microsoft 365, Microsoft Graph API, Microsoft Entra ID