news.mlab.sh
Back to the feed
threat-intel

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

High
Image: The Hacker News
Summary

The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution. Recent findings reveal a shift towards utilizing legitimate services like Google Apps Script and Microsoft 365 calendars to blend C2 traffic with normal network activity, alongside a new communication module (GoogleService.dll) and an inter-component broker (rnp.dll). The framework’s modular design and reliance on AI are further enhancing its evasion capabilities and operational tempo, as evidenced by APT42’s recent use of TAMECAT for spear-phishing targeting the nuclear energy sector.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.