Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Summary
Cybersecurity researchers have uncovered new components of the Cavern (Cav3rn) command-and-control framework. This framework is utilized by Iranian nation-state hackers in attacks targeting entities in Israel, and its evolution has been monitored since December 2025.
IFF Assessment
FOE
The discovery of an evolving C2 framework used by nation-state actors represents an advancement in their capabilities, posing a greater threat to defenders.
Defender Context
The continued development of sophisticated C2 frameworks like Cavern by nation-state actors highlights the persistent threat of advanced persistent threats (APTs). Defenders should be aware of techniques that blend malicious traffic with legitimate channels, such as DNS and cloud applications, to evade detection.