Zero Day Room
Live
Incidents

Cavern C2 Framework Evolves with New Communication Module and Google Apps Script Relay

Kaspersky researchers have discovered new components in the Cavern command-and-control framework used by Iranian nation-state hackers, expanding its communication capabilities and allowing it to blend in with legitimate traffic.

Kaspersky researchers have discovered new components in the Cavern command-and-control framework used by Iranian...

The Cavern command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting entities in Israel, has continued to evolve with new components discovered by Kaspersky researchers.

Cavern, first publicly documented by Check Point Research in early July 2026, consists of multiple moving parts, including an Agent and an assortment of modules, that work in tandem to enable mission-specific post-exploitation functionality, while minimizing forensic visibility and ensuring persistent access.

The modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling.

Kaspersky researchers have discovered a new communication module, GoogleService.dll, which reads a configuration file from disk ("conf.json") and performs a DNS A-record query to opt for either a direct HTTPS or a Google Apps Script relay for each transaction.

When the Google mode is selected, the module sends requests to the Apps Script deployment, which then forwards them to the threat actor-controlled backend. If Direct HTTPS is chosen by DNS, it contacts the configured address without using the relay.

The cybersecurity vendor also discovered an inter-component broker ("rnp.dll") that functions as the framework's local bridge, which discovers and loads DLL components, routes messages between them, and supports runtime upgrades.

The development is a sign of ongoing evolution of the Cavern framework, while relying on legitimate services to evade conventional perimeter defenses.

"By abusing legitimate services - previously Outlook calendar events and now Google Apps Script - the framework blends its C2 traffic with normal network activity, complicating network-based detection," Kaspersky said.

### Cavern's Modular Design and Operational Tempo

The Cavern framework's shift to a modular, extensible architecture using a plugin-based system is assessed to have taken place in late April 2026.

This modular design allows the framework to expand its capabilities and adapt to new situations, making it a more resilient and effective tool for the Iranian nation-state hackers.

"Given its development pace, modular design, and operational tempo, we assess that CAV3RN will likely continue to expand," Kaspersky said.

### APT42 Resurfaces with TAMECAT

The disclosure comes as DarkAtlas detailed APT42's use of TAMECAT in spear-phishing attacks targeting individuals associated with the nuclear energy sector as recently as April and May 2026 via LNK files masquerading as PDF documents.

The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.

The Iranian hacking group has also been observed using generative artificial intelligence (AI) as a way to accelerate operations, including developing specialized tooling, researching exploitation techniques, language translation, and identifying official email addresses, and investigating entities of interest.

"APT42 remains an intelligence-collection threat whose advantage comes from patient human targeting, now accelerated by AI and supported by more resilient malware when needed," DarkAtlas said.

Related coverage

More from Incidents