Cavern C2: New Insights into Iranian Cyber Attacks
Kaspersky reports on the evolution of the Cavern C2 framework, which is used by Iranian hackers for attacks on Israel.
Cybersecurity researchers have investigated the ongoing evolution of the Cavern (also known as Cav3rn) Command-and-Control (C2) Framework used by Iranian state hackers. These attacks specifically target various organizations in Israel. According to a report from the Russian cybersecurity company Kaspersky, which has been monitoring the threat activities since December 2025, new, previously unreported components have been discovered that expand the functionality of the framework.
The discovery of these new components shows that Iranian hackers are continuously adapting their techniques and tactics to make their attacks more effective. Kaspersky highlights that the use of DNS (Domain Name System) and Google Apps Script allows the attackers to blend better into legitimate traffic. This method makes it more difficult for security authorities to identify and block the malicious activities.
Technical Details of the Cavern C2 Framework
The Cavern C2 Framework employs a variety of techniques to obscure communication between compromised systems and the Command-and-Control servers. The integration of DNS queries into the traffic allows the attackers to disguise their activities and pose as legitimate users. This technique is particularly effective as it is often not detected by conventional security solutions.
In addition to the DNS techniques, Kaspersky has also found that Google Apps Script is integrated into the attacks. This scripting language, originally developed for automating tasks in Google services, is misused by hackers to carry out malicious activities. The use of widely used and trusted platforms like Google increases the likelihood that the attacks remain undetected.
Kaspersky researchers have also noted that the attacks target a variety of sectors, including government agencies, critical infrastructures, and private companies. This broad selection of targets suggests that Iranian hackers are attempting to destabilize not only military but also economic and societal objectives.
Reactions and Security Measures
Kaspersky's findings have raised concerns among security authorities in Israel and other affected countries. Israeli cybersecurity authorities have increased their warnings about potential attacks and advise organizations to review and strengthen their security protocols. Implementing layered security measures is considered crucial to minimize the risks posed by such advanced threats.
In addition to national security measures, private companies have also begun to revise their cyber defense strategies. Many organizations are focusing on employee training to raise awareness of phishing and other attack methods. Raising awareness of the dangers posed by such advanced attacks is an important step towards improving the overall security situation.
The developments surrounding the Cavern C2 Framework highlight the ongoing threat posed by state-sponsored hacker groups. The ability of these groups to adapt to new technologies and methods presents a significant challenge for the cybersecurity community. Continuous monitoring and analysis of such threats is essential to develop effective countermeasures.
comment Kommentare (0)
Noch keine Kommentare. Schreiben Sie den ersten!
Kommentar hinterlassen