Executive Summary
In August 2026, cybersecurity researchers identified advancements in the Cavern (aka Cav3rn) command-and-control (C2) framework, utilized by Iranian nation-state hackers targeting Israeli entities. The updated framework incorporates a complex C2 module that leverages DNS A-record responses to dynamically select between direct HTTPS communication and a Google Apps Script relay for each transaction. This evolution enhances the framework's ability to blend malicious traffic with legitimate network activity, complicating detection efforts. The Cavern framework, first documented in July 2026, is associated with the Cavern Manticore group, linked to Iran's Ministry of Intelligence and Security (MOIS), and shares overlaps with other Iranian threat actors such as MuddyWater and Lyceum. The modular architecture of Cavern facilitates various post-exploitation activities, including file operations, database enumeration, Active Directory reconnaissance, and network tunneling. The integration of legitimate services like Google Apps Script and Microsoft 365 calendars into its C2 channels underscores a strategic shift towards more covert and resilient communication methods. This development highlights the increasing sophistication of nation-state cyber operations and the challenges in detecting and mitigating such threats.
Why This Matters Now
The Cavern C2 framework's use of legitimate services for command-and-control communication represents a significant evolution in cyber-espionage tactics, making detection and mitigation more challenging. Organizations must enhance their security measures to identify and respond to such sophisticated threats promptly.
Attack Path Analysis
The attackers gained initial access by exploiting vulnerabilities in Remote Monitoring and Management (RMM) software used by IT providers, deploying the Cavern C2 framework through DLL sideloading techniques. Once inside, they escalated privileges by leveraging the modular capabilities of Cavern to perform Active Directory reconnaissance and credential harvesting. Utilizing the compromised credentials, the attackers moved laterally across the network, accessing critical systems and data repositories. They established command and control channels by abusing legitimate services like Google Apps Script and DNS tunneling to evade detection. Sensitive data was exfiltrated through these covert channels, blending malicious traffic with normal network activity. The impact included unauthorized access to confidential information, potential disruption of services, and compromise of critical infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attackers exploited vulnerabilities in Remote Monitoring and Management (RMM) software used by IT providers, deploying the Cavern C2 framework through DLL sideloading techniques.
MITRE ATT&CK® Techniques
Application Layer Protocol: DNS
Protocol Tunneling
Command and Scripting Interpreter: JavaScript
System Binary Proxy Execution: Rundll32
Valid Accounts: Cloud Accounts
Dynamic Resolution: DNS Calculation
Proxy: Internal Proxy
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for security monitoring and testing are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical infrastructure targeted by Iranian nation-state actors using Cavern C2 framework, with energy sector entities historically compromised by OilRig operations.
Government Administration
High-value espionage target for Iranian MOIS-affiliated groups using DNS tunneling and Microsoft 365 calendar exploitation to evade government perimeter defenses.
Defense/Space
Nuclear energy sector specifically targeted by APT42 spear-phishing campaigns using TAMECAT malware for intelligence collection and surveillance operations against defense contractors.
Information Technology/IT
Microsoft 365 and Google Apps Script abuse creates significant risk for IT infrastructure managing enterprise communications and cloud service authentication mechanisms.
Sources
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffichttps://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.htmlVerified
- Project CAV3RN uses Google Apps Script for stealthy C2 in Israelhttps://securelist.com/project-cav3rn-continues/120991/Verified
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizationshttps://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit RMM software vulnerabilities may have been limited, reducing the likelihood of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may have been constrained, limiting their access to sensitive systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement could have been significantly restricted, reducing their ability to access critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may have been detected and disrupted, hindering their ability to maintain control.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could have been identified and blocked, preventing unauthorized data transfer.
The overall impact of the attack could have been minimized, reducing unauthorized access and service disruptions.
Impact at a Glance
Affected Business Functions
- IT Service Management
- Government Operations
- Data Security
- Network Infrastructure
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive government and corporate data, including confidential communications and strategic plans.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access controls.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Enhance Threat Detection & Anomaly Response capabilities to rapidly identify and mitigate suspicious behaviors.



