VMTech
Discuss a project

Kaspersky Finds Cavern C2 Switching Between DNS, HTTPS and Apps Script

Kaspersky Finds Cavern C2 Switching Between DNS, HTTPS and Apps Script

Kaspersky has identified a new Cavern, also known as Cav3rn, command-and-control module that uses DNS A-record responses to select either direct HTTPS communications or a Google Apps Script relay for each transaction. The framework has been used against entities in Israel and is linked to the Iran-affiliated Cavern Manticore activity cluster.

The newly described component, GoogleService.dll, reads its settings from a local conf.json file. It makes a DNS A-record query, then follows the returned instruction: in Google mode it sends requests to an Apps Script deployment that forwards traffic to an actor-controlled backend; in direct mode it contacts the configured address without the relay.

Kaspersky said the same DNS infrastructure can validate and replace the Google Apps Script deployment ID. That gives operators a way to rotate the Google channel while retaining the broader communication design.

Modular C2 expands its communication options

Cavern is a modular, plugin-based post-exploitation framework. Its Agent and modules support file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, SOCKS5 proxying and WebSocket tunnelling. Kaspersky assesses that the move to a modular and extensible architecture occurred in late April 2026.

The researchers also found rnp.dll, an inter-component broker that discovers and loads DLL components, routes messages between them and supports runtime upgrades. This local bridge adds flexibility to a framework designed for persistent access and reduced forensic visibility.

The primary domain associated with this activity, studiotikva[.]com, was first registered in February 2024. It expired in February 2026 and was re-registered three months later, Kaspersky said.

Legitimate services complicate network detection

The new module follows reports on HOLLOWGRAPH, another Cavern component that used Microsoft 365 calendars as a two-way dead-drop through the Microsoft Graph API. Operators could place tasking in calendar events, while the implant created events carrying encrypted data in file attachments; the events were dated 13 May 2050 to avoid attracting the mailbox owner’s attention.

HOLLOWGRAPH also used DNS tunnelling to refresh Microsoft Entra ID, formerly Azure AD, credentials used to authenticate to the Graph API. Kaspersky has linked Cavern to OilRig, also called APT34, with low confidence, citing operational indicators rather than direct code reuse or infrastructure overlap. The cluster has overlaps with MuddyWater and the OilRig subgroup Lyceum.

For security teams tracking related Iranian activity, C2 operations in the Middle East provides context on C2 operations in the Middle East, while the Cavern findings reinforce the need to correlate DNS requests, outbound HTTPS and use of approved cloud services. DNS responses that steer traffic, unusual Apps Script deployments and unexpected service-to-service connections deserve investigation even when the destination appears legitimate.

Business implication

Businesses should monitor DNS and cloud-service telemetry together, establish expected use of Google Apps Script and Microsoft 365 APIs, and investigate deviations from those baselines, because trusted services can be incorporated into command-and-control paths.

#cybersecurity#threatintel#dnsscurity#cloudsecurity
Open analytics
On the site 0 views
min read 4 17.08.2026
Instagram

Kaspersky Finds Cavern C2 Switching Between DNS, HTTPS and Apps Script

Open the post on Instagram ↗