Return to Threats

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

thehackernews.com 2026-08-17 malicious AI use Medium

What Happened

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

Why It Matters

Report facts: The article describes the evolution of the Cavern (Cav3rn) command-and-control framework used by Iranian nation-state actors, leveraging DNS and Google Apps Script to better blend C2 traffic into what appears to be legitimate network activity targeting Israeli entities. RealGround analysis: While the report is focused on traditional cyber C2 infrastructure rather than AI systems, the same evasion and living-off-the-land techniques can be adapted to hide malicious AI-agent orchestration or data exfiltration via seemingly benign cloud services. Organizations should treat this as a signal to continuously red-team AI-enabled workflows for covert command channels and abuse of SaaS and cloud scripting platforms that could be used to control or manipulate AI agents without detection.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html

Talk to AI CISO