Kaspersky Details Cavern C2 Framework Evolution Blending DNS and Google Apps Script
Iranian Nation-State Actors Target Entities in Israel with Advanced Command-and-Control Infrastructure

Key Takeaways
- Kaspersky has been monitoring the Cavern C2 framework since December 2025.
- The framework is attributed to Iranian nation-state hackers targeting entities in Israel.
- New components enable the use of DNS tunneling and Google Apps Script for C2.
- Blending into legitimate traffic makes detection difficult for defenders.
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




