Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

August 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Israeli governmental and private entities
Incident: Deployment of a modular C2 framework using cloud-relay and calendar-based exfiltration.
Impact: Long-term stealthy persistence and exfiltration of sensitive organizational data.
Attacker: Cavern Manticore (Iranian MOIS)
Analysis: The Cavern C2 framework utilizes a sophisticated modular approach to maintain stealthy access. By leveraging DNS responses and legitimate cloud services like Google and Microsoft Graph API, the attackers blend command-and-control traffic with normal business activity. The use of dead-drop calendar events dated far into the future highlights a creative attempt to evade human detection.
Recommendations: Monitor for unusual Microsoft Graph API calls and unauthorized calendar event modifications.; Implement strict DNS filtering and analyze A-record anomalies for C2 patterns.; Audit Google Apps Script activity and API usage within corporate cloud environments.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *