Skip to content

Security1 publisher3 min readPublished

Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing

Kaspersky says an Iranian-linked framework now picks its channel per transaction from a DNS record, and can swap the Google relay behind it. Allowlisted SaaS domains carry the traffic.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Kaspersky traced the continued evolution of the Cavern (aka Cav3rn) command-and-control framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
  • Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 led to the discovery of previously unreported components that expand the toolkit's communication capabilities.
  • Kaspersky: "The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction."
  • Kaspersky: "The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."
  • Cavern was first publicly documented by Check Point Research in early July 2026, and consists of multiple parts including an Agent and an assortment of modules for mission-specific post-exploitation while minimizing forensic visibility and ensuring persistent access.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Kaspersky says the Cavern framework, used by Iranian nation-state operators against targets in Israel, now ships a communication module that queries a DNS A-record before each transaction to decide whether to reach its backend over direct HTTPS or through a Google Apps Script relay [1][2][3]. The same DNS infrastructure can validate and replace the relay's deployment ID, so the Google leg is not a fixed dependency but a rotatable one the operator controls remotely [4].

The module, GoogleService.dll, reads a configuration file from disk called conf.json and then performs the A-record lookup to select its mode [13]. In Google mode, requests go to the Apps Script deployment, which forwards them to the attacker-controlled backend; in direct mode it simply contacts the configured address [14]. Kaspersky also found an inter-component broker, rnp.dll, that discovers and loads DLL components, routes messages between them, and supports runtime upgrades [15]. That is the part worth sitting with: the transport is a plugin, the relay identity is a variable, and the switch is a DNS answer.

This is the second trusted-SaaS channel documented in the same toolkit. Group-IB and Kaspersky previously described HOLLOWGRAPH, a module that abuses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead drop, with DNS tunneling used to refresh the Entra ID credentials behind the Graph calls [8]. According to Group-IB, operators plant tasking as calendar events and the implant exfiltrates files as attachments, with every event dated to 13 May 2050 so the mailbox owner does not notice [9]. HOLLOWGRAPH, a .NET NativeAOT-compiled DLL, was first seen in the wild on 7 June 2026 [10], roughly a month before Check Point Research published the first public account of Cavern in early July 2026 [5][18].

The broader module set covers file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force, network reconnaissance, and SOCKS5 and WebSocket tunneling [6]. Kaspersky assesses the shift to a plugin-based architecture happened in late April 2026, and links the activity to OilRig, also called APT34, with low confidence, noting no direct code reuse or infrastructure overlap [11]. The cited indicators are circumstantial: use of Microsoft-hosted services for C2 as in RDAT and OilCheck, a secondary mechanism for obtaining replacement OAuth refresh tokens as in OilBooster, and use of compromised infrastructure inside targeted regions as in Solar and Veaty [12]. Cavern C2 has separately been tied to Cavern Manticore, a group affiliated with Iran's Ministry of Intelligence and Security with overlaps to MuddyWater and the OilRig sub-group Lyceum [7].

Kaspersky's own summary is that abusing legitimate services, previously Outlook calendar events and now Google Apps Script, blends the C2 traffic with normal network activity and complicates network-based detection [17]. For anyone running an egress allowlist keyed to reputable SaaS domains, that is the whole problem stated plainly: the exception was written to keep business tools working, and it now underwrites the channel.

Watch three things. Whether published Apps Script deployment IDs retain any indicator value given that DNS can rotate them [4]. Whether the low-confidence OilRig attribution firms up or gets withdrawn [11]. And the infrastructure hygiene signal: the primary domain studiotikva[.]com was registered in February 2024, expired in February 2026, then re-registered three months later, around May 2026 [16][19]. Expired-then-revived domains are cheap to monitor and this cluster keeps using them.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories