Executive Summary
In August 2026, Kaspersky researchers identified an evolution in the Project CAV3RN cyberespionage framework, which has been targeting Israeli organizations since December 2025. The latest development involves a sophisticated command-and-control (C2) module that utilizes Google Apps Script as a relay and employs DNS-based mechanisms for C2 channel selection. This approach allows the malware to blend its communication with legitimate network traffic, thereby evading traditional detection methods. The framework's modular design and rapid development indicate a persistent and adaptable threat.
The significance of this incident lies in the increasing trend of threat actors leveraging legitimate cloud services to obfuscate malicious activities. By integrating Google Apps Script and DNS-based techniques, Project CAV3RN exemplifies the challenges in distinguishing between normal and malicious network behavior, underscoring the need for advanced detection strategies.
Why This Matters Now
The use of legitimate cloud services like Google Apps Script for malicious purposes highlights the evolving tactics of cyber threat actors. Organizations must enhance their security measures to detect and mitigate such sophisticated threats that exploit trusted platforms.
Attack Path Analysis
The Project CAV3RN attack began with the deployment of a modular espionage framework targeting systems in Israel. The attackers then escalated privileges to gain deeper access within the compromised environment. Utilizing the framework's modular design, they moved laterally across the network to identify and access additional systems. For command and control, the attackers employed a sophisticated module that used DNS A-record responses to select between direct HTTPS and Google Apps Script as communication channels. This setup allowed them to exfiltrate data covertly, blending malicious traffic with normal network activity. The impact of the attack was significant, leading to unauthorized access and potential data breaches.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Deployment of the Project CAV3RN modular espionage framework targeting systems in Israel.
MITRE ATT&CK® Techniques
Application Layer Protocol: DNS
Dynamic Resolution: Fast Flux DNS
Inter-Process Communication: Component Object Model
Application Layer Protocol: Web Protocols
Web Service: Dead Drop Resolver
Encrypted Channel: Symmetric Cryptography
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment Segmentation
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
CAV3RN espionage framework targeting Israeli entities poses critical threat to government systems through encrypted C2 channels and lateral movement capabilities.
Defense/Space
Modular espionage framework with Google Apps Script relay creates severe national security risks requiring enhanced east-west traffic monitoring and segmentation.
Information Technology/IT
Multi-transport C2 communication exploiting cloud services demands strengthened egress filtering, zero trust segmentation, and multicloud visibility controls for protection.
Computer Software/Engineering
Framework's DNS-based C2 selection and runtime upgrades threaten software development environments, requiring enhanced threat detection and anomaly response capabilities.
Sources
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionhttps://securelist.com/project-cav3rn-continues/120991/Verified
- New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoveryhttps://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to the Project CAV3RN attack as it enforces strict segmentation and controlled communication paths, which would likely limit the attacker's ability to move laterally and exfiltrate data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be constrained, reducing the scope of compromised systems.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be limited, reducing the depth of access within the environment.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained, reducing the number of systems they could access.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications would likely be detected and restricted, reducing their ability to manage compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be constrained, reducing the volume of data they could extract.
The overall impact of the attack would likely be reduced, limiting unauthorized access and data breaches.
Impact at a Glance
Affected Business Functions
- n/a
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement and enforce least privilege access.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows.
- • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.



