Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution. Recent findings reveal a shift towards utilizing legitimate services like Google Apps Script and Microsoft 365 calendars to blend C2 traffic with normal network activity, alongside a new communication module (GoogleService.dll) and an inter-component broker (rnp.dll). The framework’s modular design and reliance on AI are further enhancing its evasion capabilities and operational tempo, as evidenced by APT42’s recent use of TAMECAT for spear-phishing targeting the nuclear energy sector.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
