CyberNews
← Back to dashboard
RESEARCH Kaspersky Securelist

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Aug 11, 2026, 10:00 AM · by Kaspersky Securelist

Project CAV3RN continues to target Israel with an evolving command-and-control (C2) architecture that leans heavily on legitimate cloud services. In this latest iteration, operators use Google Apps Script as a relay for C2 communications and rely on DNS-based channel selection to steer traffic between C2 routes, making the campaign significantly harder to sinkhole or block at the network edge. The framework is a modular .NET NativeAOT implementation, compiled ahead of time so the payloads are smaller, faster to load, and far more difficult to analyze statically. Each module is delivered independently, letting the operators swap or extend components without redeploying the entire toolset. By blending C2 traffic with genuine Google services and using DNS records to recover configuration and select active channels, the malware avoids dedicated infrastructure and evades many network-level detections. Defenders are advised to monitor for anomalous DNS queries and outbound traffic toward Google Apps Script endpoints in environments with exposure to Israel-based assets.

Source: Kaspersky Securelist