Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Kaspersky tracks Project CAV3RN routing C2 through Google Apps Script and using DNS records to dynamically select channels, hiding in traffic that enterprises rarely block.
Summary written by editorial AI · Source link below
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
Editorial Analysis
Abuse of trusted cloud services like Google Apps Script for C2 communication defeats traditional domain-blocking strategies and demands behaviour-based detection approaches.
Evaluate whether your DLP and CASB solutions can inspect and alert on abnormal Google Apps Script usage patterns originating from endpoints.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Securelist (Kaspersky) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d