Project CAV3RN Enhances Espionage Tactics Using Google Apps Script and DNS

Project CAV3RN Enhances Espionage Tactics Using Google Apps Script and DNS

First seen 12 Aug 2026, 10:24 UTC SecurelistGbhackersCybersecuritynews 82% similarity 72.5

Article Content

Browse articles
ThreatCluster

Project CAV3RN is a modular cyberespionage framework targeting organizations in Israel. Recent developments reveal its use of a sophisticated command-and-control (C2) design that dynamically combines direct HTTPS traffic with Google Apps Script relays. This approach enhances resilience and network camouflage, allowing operators to avoid detection. The framework's architecture includes a local broker that manages DLL components and facilitates runtime upgrades. Key components like GoogleService.dll have been identified, which utilize DNS A-record responses to determine the communication method for each transaction. The framework's ongoing evolution indicates a significant threat to Israeli organizations, with potential implications for broader cybersecurity. The attack method leverages existing cloud services to obscure malicious activities.

Key Points: • Project CAV3RN targets Israeli organizations with advanced cyberespionage techniques. • The framework uses Google Apps Script and DNS to obscure command-and-control traffic. • Recent findings indicate a focus on resilience and modularity in its architecture.

ThreatCluster AI How this analysis works

Timeline

2026-06-01
Initial report on Project CAV3RN published
Kaspersky Threat Intelligence Reporting service documented the framework's initial capabilities.
Securelist
2026-07-01
Follow-up report details evolving architecture
Securelist published additional findings on Project CAV3RN's architecture and C2 capabilities.
Securelist
2026-08-11
New components identified in Project CAV3RN
Securelist reported on previously undocumented components enhancing the framework's communication capabilities.
Securelist
2026-08-12
Gbhackers report on Project CAV3RN's tactics
Gbhackers highlighted the use of Google Apps Script and DNS for hiding C2 traffic in cyberespionage attacks.
Gbhackers

Community

Browse all →