Iranian nation-state operators continue to refine the Cavern C2 framework with new obfuscation techniques designed to evade detection. Kaspersky researchers monitoring the threat group since December 2025 have identified previously unreported components that leverage DNS tunneling and Google Apps Script to disguise malicious communications as legitimate traffic.
Cavern, also tracked as Cav3rn, operates as a command-and-control platform deployed in attacks targeting Israeli entities. The framework's latest evolution demonstrates sophisticated operational security practices. By routing C2 traffic through DNS protocols and abusing Google's Apps Script infrastructure, threat actors obscure their command channels within benign-looking network flows. DNS-based C2 relies on standard domain name queries that blend seamlessly into normal internet activity, making detection difficult for network monitoring tools. Google Apps Script, a cloud-based automation platform, offers similar camouflage when weaponized for command delivery.
The new components identified by Kaspersky expand Cavern's functional capabilities, though specifics remain limited in current reporting. The discovery underscores a broader trend among state-sponsored groups who continuously iterate on existing toolsets rather than developing entirely new frameworks. This approach reduces development overhead while maintaining operational effectiveness against target defenses.
Organizations defending against this threat should implement DNS traffic analysis and egress filtering to identify suspicious domain queries. Google Workspace administrators should monitor unusual Apps Script activity and enforce strict API permissions. Network detection and response (NDR) solutions capable of identifying DNS anomalies offer practical detection mechanisms.
The attribution to Iranian operators reflects their sustained focus on Israeli targets and their demonstrated investment in developing reliable, stealthy C2 infrastructure. As capabilities mature, defenders must adapt detection strategies beyond signature-based approaches to behavioral analysis that identifies command patterns regardless of delivery mechanism.
