Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Kaspersky tracks Project CAV3RN routing C2 through Google Apps Script and using DNS records to dynamically select channels, hiding in traffic that enterprises rarely block.

Summary written by editorial AI · Source link below

Filed by Securelist (Kaspersky)1 min readRead at source ↗

Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.

Editorial Analysis

Why it matters

Abuse of trusted cloud services like Google Apps Script for C2 communication defeats traditional domain-blocking strategies and demands behaviour-based detection approaches.

What to do

Evaluate whether your DLP and CASB solutions can inspect and alert on abnormal Google Apps Script usage patterns originating from endpoints.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Securelist (Kaspersky)

External link — opens at Securelist (Kaspersky) in a new tab.

§
Continue with

More from the Threat Intel Desk