Cavern C2 evolves, abusing DNS and Google Apps
🔍 Kaspersky researchers uncovered new components of the Cavern (CAV3RN) command-and-control framework used by Iranian-linked operators to target Israeli entities, revealing a module that switches between direct HTTPS and a Google Apps Script relay using DNS A-record responses. The modular toolkit supports extensive post-exploitation functions and minimizes forensic visibility, while additional reports show HOLLOWGRAPH abusing Microsoft 365 calendars and DNS tunneling to maintain and refresh Azure AD credentials. The findings highlight a shift to a plugin-based architecture and continued use of legitimate services to evade detection.
