Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cavern Framework Evolves with New DNS and Google Apps Integration

Cavern Framework Evolves with New DNS and Google Apps Integration

Posted on August 17, 2026 By CWS

Cybersecurity experts have identified continued advancements in the Cavern command-and-control (C2) framework, used by Iranian hackers against targets in Israel. This evolution aims to blend malicious traffic with legitimate online activities.

New Communication Methods Discovered

Russian cybersecurity firm Kaspersky has been monitoring this threat since December 2025, revealing new components that enhance Cavern’s communication methods. A notable discovery is a sophisticated C2 module that chooses between using DNS A-records and Google Apps Script for communication, creating challenges for defense mechanisms.

First reported by Check Point Research in July 2026, Cavern is composed of various elements such as an Agent and multiple modules, enabling specific post-exploitation tasks while reducing detection and ensuring persistent access. These modules are equipped to handle file operations, network reconnaissance, and more.

Integration with Microsoft Services

Kaspersky and Group-IB have uncovered another module, HOLLOWGRAPH, which uses Microsoft 365 calendars as covert C2 channels. This malware exploits the Microsoft Graph API to extract data and send commands using calendar events, cleverly avoiding detection by setting events far into the future.

The malware also employs DNS tunneling to refresh credentials, utilizing a .NET NativeAOT-compiled DLL first seen in June 2026. The integration of legitimate services into Cavern’s framework complicates detection efforts, as the malicious traffic is masked within normal network operations.

Implications and Future Outlook

Kaspersky has linked Cavern’s modular architecture to OilRig, although with low confidence, due to certain similarities in tactics but without direct code or infrastructure overlap. This evolution signifies an ongoing adaptation to avoid detection by leveraging trusted services.

Meanwhile, APT42, another Iranian group, has been using TAMECAT in spear-phishing campaigns targeting the nuclear sector, highlighting a trend towards advanced social engineering tactics. This group’s operations are reportedly accelerated by AI, which helps in developing tools and conducting research.

The continuous development of the Cavern framework, with its reliance on legitimate services like Google Apps Script, poses a persistent threat to cybersecurity. As these frameworks evolve, organizations must stay vigilant and adapt their defenses accordingly.

The Hacker News Tags:APT34, APT42, Cavern C2, Cybersecurity, DarkAtlas, DNS tunneling, Google Apps Script, Iranian hackers, Kaspersky, Microsoft Graph API, OilRig

Post navigation

Previous Post: Critical Flaw in Forminator Plugin Allows Remote Code Execution
Next Post: Mustang Panda’s Enhanced CoolClient and Rootkit Tactics

Related Posts

Anthropic AI Unearths Firefox Security Flaws Anthropic AI Unearths Firefox Security Flaws The Hacker News
Critical Adobe Campaign Flaw Poses Code Execution Risk Critical Adobe Campaign Flaw Poses Code Execution Risk The Hacker News
Fake Software Installers Threaten Windows Security Fake Software Installers Threaten Windows Security The Hacker News
See Threats to Your Industry & Country in Real Time See Threats to Your Industry & Country in Real Time The Hacker News
GoCaracal Malware Uses Ethereum for C2 Address Updates GoCaracal Malware Uses Ethereum for C2 Address Updates The Hacker News
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach
  • Exploited Zammad Flaws Enable Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach
  • Exploited Zammad Flaws Enable Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark