Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cavern Framework Evolves with New DNS and Google Apps Integration

Cavern Framework Evolves with New DNS and Google Apps Integration

Posted on August 17, 2026 By CWS

Cybersecurity experts have identified continued advancements in the Cavern command-and-control (C2) framework, used by Iranian hackers against targets in Israel. This evolution aims to blend malicious traffic with legitimate online activities.

New Communication Methods Discovered

Russian cybersecurity firm Kaspersky has been monitoring this threat since December 2025, revealing new components that enhance Cavern’s communication methods. A notable discovery is a sophisticated C2 module that chooses between using DNS A-records and Google Apps Script for communication, creating challenges for defense mechanisms.

First reported by Check Point Research in July 2026, Cavern is composed of various elements such as an Agent and multiple modules, enabling specific post-exploitation tasks while reducing detection and ensuring persistent access. These modules are equipped to handle file operations, network reconnaissance, and more.

Integration with Microsoft Services

Kaspersky and Group-IB have uncovered another module, HOLLOWGRAPH, which uses Microsoft 365 calendars as covert C2 channels. This malware exploits the Microsoft Graph API to extract data and send commands using calendar events, cleverly avoiding detection by setting events far into the future.

The malware also employs DNS tunneling to refresh credentials, utilizing a .NET NativeAOT-compiled DLL first seen in June 2026. The integration of legitimate services into Cavern’s framework complicates detection efforts, as the malicious traffic is masked within normal network operations.

Implications and Future Outlook

Kaspersky has linked Cavern’s modular architecture to OilRig, although with low confidence, due to certain similarities in tactics but without direct code or infrastructure overlap. This evolution signifies an ongoing adaptation to avoid detection by leveraging trusted services.

Meanwhile, APT42, another Iranian group, has been using TAMECAT in spear-phishing campaigns targeting the nuclear sector, highlighting a trend towards advanced social engineering tactics. This group’s operations are reportedly accelerated by AI, which helps in developing tools and conducting research.

The continuous development of the Cavern framework, with its reliance on legitimate services like Google Apps Script, poses a persistent threat to cybersecurity. As these frameworks evolve, organizations must stay vigilant and adapt their defenses accordingly.

The Hacker News Tags:APT34, APT42, Cavern C2, Cybersecurity, DarkAtlas, DNS tunneling, Google Apps Script, Iranian hackers, Kaspersky, Microsoft Graph API, OilRig

Post navigation

Previous Post: Critical Flaw in Forminator Plugin Allows Remote Code Execution
Next Post: Mustang Panda’s Enhanced CoolClient and Rootkit Tactics

Related Posts

Trojanized NuGet Package Alters Online Betting Results Trojanized NuGet Package Alters Online Betting Results The Hacker News
Cybersecurity Threats: SMS Blaster, OpenEMR, and Roblox Hacks Cybersecurity Threats: SMS Blaster, OpenEMR, and Roblox Hacks The Hacker News
4 Outdated Habits Destroying Your SOC’s MTTR in 2026 4 Outdated Habits Destroying Your SOC’s MTTR in 2026 The Hacker News
Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero The Hacker News
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild The Hacker News
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark