Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Summary

Cybersecurity researchers have uncovered new components of the Cavern (Cav3rn) command-and-control framework. This framework is utilized by Iranian nation-state hackers in attacks targeting entities in Israel, and its evolution has been monitored since December 2025.

IFF Assessment

FOE

The discovery of an evolving C2 framework used by nation-state actors represents an advancement in their capabilities, posing a greater threat to defenders.

Defender Context

The continued development of sophisticated C2 frameworks like Cavern by nation-state actors highlights the persistent threat of advanced persistent threats (APTs). Defenders should be aware of techniques that blend malicious traffic with legitimate channels, such as DNS and cloud applications, to evade detection.

Read Full Story →