hacker-news · Crawled Aug 17, 2026

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

1 IoCs 4 Actors 1 Malware
Read original article ↗

AI Summary

Iranian nation-state actors linked to Cavern (aka Cav3rn) C2 framework have evolved their infrastructure to blend malicious traffic with legitimate services, using DNS A-record queries to dynamically switch between direct HTTPS and Google Apps Script relays for command-and-control. A new module, HOLLOWGRAPH, abuses Microsoft 365 calendars via the Graph API to exfiltrate data and receive commands, with events scheduled far into the future to avoid detection. The framework uses a modular architecture with components like GoogleService.dll and rnp.dll, leveraging legitimate cloud services to evade perimeter defenses and maintain persistence.

AI-extracted · verify before operational use

Extracted Entities 5 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain studiotikva[.]com Details →

MITRE ATT&CK TTPs 41 techniques

T1001.002 Steganography · Command And Control T1003 OS Credential Dumping · Credential Access T1003.002 Security Account Manager · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1132.001 Standard Encoding · Command And Control T1204.002 Malicious File · Execution T1219 Remote Access Software · Command And Control T1486 Data Encrypted for Impact · Impact T1543.003 Windows Service · Persistence T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1574.002 DLL Side-Loading · Persistence T1588 Obtain Capabilities · Resource Development T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1059.003 Windows Command Shell · Execution T1102 Web Service · Command And Control T1114 Email Collection · Collection T1558 Steal or Forge Kerberos Tickets · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1583 Acquire Infrastructure · Resource Development