Security1 distinct publisher3 min readUpdated
Kaspersky says an Iranian-linked framework now picks its channel per transaction from a DNS record, and can swap the Google relay behind it. Allowlisted SaaS domains carry the traffic.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Kaspersky says the Cavern framework, used by Iranian nation-state operators against targets in Israel, now ships a communication module that queries a DNS A-record before each transaction to decide whether to reach its backend over direct HTTPS or through a Google Apps Script relay [1][2][3]. The same DNS infrastructure can validate and replace the relay's deployment ID, so the Google leg is not a fixed dependency but a rotatable one the operator controls remotely [4].
The module, GoogleService.dll, reads a configuration file from disk called conf.json and then performs the A-record lookup to select its mode [13]. In Google mode, requests go to the Apps Script deployment, which forwards them to the attacker-controlled backend; in direct mode it simply contacts the configured address [14]. Kaspersky also found an inter-component broker, rnp.dll, that discovers and loads DLL components, routes messages between them, and supports runtime upgrades [15]. That is the part worth sitting with: the transport is a plugin, the relay identity is a variable, and the switch is a DNS answer.
This is the second trusted-SaaS channel documented in the same toolkit. Group-IB and Kaspersky previously described HOLLOWGRAPH, a module that abuses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead drop, with DNS tunneling used to refresh the Entra ID credentials behind the Graph calls [8]. According to Group-IB, operators plant tasking as calendar events and the implant exfiltrates files as attachments, with every event dated to 13 May 2050 so the mailbox owner does not notice [9]. HOLLOWGRAPH, a .NET NativeAOT-compiled DLL, was first seen in the wild on 7 June 2026 [10], roughly a month before Check Point Research published the first public account of Cavern in early July 2026 [5][18].
The broader module set covers file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force, network reconnaissance, and SOCKS5 and WebSocket tunneling [6]. Kaspersky assesses the shift to a plugin-based architecture happened in late April 2026, and links the activity to OilRig, also called APT34, with low confidence, noting no direct code reuse or infrastructure overlap [11]. The cited indicators are circumstantial: use of Microsoft-hosted services for C2 as in RDAT and OilCheck, a secondary mechanism for obtaining replacement OAuth refresh tokens as in OilBooster, and use of compromised infrastructure inside targeted regions as in Solar and Veaty [12]. Cavern C2 has separately been tied to Cavern Manticore, a group affiliated with Iran's Ministry of Intelligence and Security with overlaps to MuddyWater and the OilRig sub-group Lyceum [7].
Kaspersky's own summary is that abusing legitimate services, previously Outlook calendar events and now Google Apps Script, blends the C2 traffic with normal network activity and complicates network-based detection [17]. For anyone running an egress allowlist keyed to reputable SaaS domains, that is the whole problem stated plainly: the exception was written to keep business tools working, and it now underwrites the channel.
Watch three things. Whether published Apps Script deployment IDs retain any indicator value given that DNS can rotate them [4]. Whether the low-confidence OilRig attribution firms up or gets withdrawn [11]. And the infrastructure hygiene signal: the primary domain studiotikva[.]com was registered in February 2024, expired in February 2026, then re-registered three months later, around May 2026 [16][19]. Expired-then-revived domains are cheap to monitor and this cluster keeps using them.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Kaspersky traced the continued evolution of the Cavern (aka Cav3rn) command-and-control framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 led to the discovery of previously unreported components that expand the toolkit's communication capabilities.
Kaspersky: "The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction."
Kaspersky: "The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."
Cavern was first publicly documented by Check Point Research in early July 2026, and consists of multiple parts including an Agent and an assortment of modules for mission-specific post-exploitation while minimizing forensic visibility and ensuring persistent access.
Cavern modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor tradecraft, single-outlet relay, thin published indicators
The technical account is specific and artifact-level — named modules, a config file, a DNS-driven channel selector, a rotatable relay deployment ID, a calendar dead drop with a fixed 2050 event date, and a domain lifecycle — and it draws on named research from Kaspersky, Group-IB and Check Point Research. It is weakened by reaching the cluster through a single aggregating publisher, by publishing effectively one indicator, and by the fact that the group-level attribution to OilRig is expressly low confidence with no code reuse or infrastructure overlap.
Confirmed in-the-wild operations, undisclosed scale
This is live tradecraft, not a proof of concept: the cluster has been tracked since December 2025, HOLLOWGRAPH was detected in the wild on June 7, 2026, the framework moved to a plugin architecture in late April 2026, and campaign infrastructure was renewed around May 2026. What is absent is any measure of breadth — no victim counts, sector mix, or number of observed intrusions — so operational reality is established while scale is not.
Broadly aligned, with headline framing slightly ahead of the evidence
The substantive claims are narrow, dated and hedged where hedging is warranted, and the concluding assessment about complicating network-based detection follows directly from the described mechanism. The mild overstatement is framing rather than fact: describing the channel choice as a coin flip and the relay as rotatable plumbing implies more resilience than a single published domain and one relay pattern demonstrate, and the OilRig link is likely to be read as firmer than the low-confidence label allows.
Commercial threat-intel research relayed by an ad-supported aggregator
Every technical finding originates with a security vendor publishing research that markets its detection and intelligence capability — Kaspersky and Group-IB on HOLLOWGRAPH, Kaspersky on the new modules, Check Point Research on first documentation, DarkAtlas on the adjacent APT42 material — and the reporting outlet is a traffic-driven aggregator restating those reports. That does not imply the findings are wrong, but no disinterested party verifies them, and the platforms whose services are abused are not asked to respond.
Moderate: coherent artifact-level detail, one publisher, hedged attribution
Confidence is held down mainly by cluster structure rather than by internal weakness. The mechanism claims are consistent, specific and dated, and multiple named vendors are cited; but a single publisher supplies all of it, indicators are minimal, victim scope is absent, and the group attribution is explicitly low confidence. That supports confident statements about tradecraft and timing and cautious ones about actor identity and campaign scale.
security
One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together1 distinct publisher
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
product
A dozen states, no marquee targets: the water hacks show where the attack surface actually is1 distinct publisher
build
A 160MB Attacker Workspace Is the First Real Parts List for Autonomous Intrusion1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026