Kaspersky Uncovers New Communication Techniques In Cavern Cyber Espionage Framework

Kaspersky Uncovers New Communication Techniques In Cavern Cyber Espionage Framework

Cybersecurity researchers have uncovered new developments in the Cavern, also known as Cav3rn, command and control framework that has been linked to Iranian nation state hackers targeting organizations in Israel. According to Russian cybersecurity company Kaspersky, continued monitoring of the threat activity since December 2025 has revealed previously undocumented components that significantly expand the framework’s communication capabilities. The latest findings show that attackers are increasingly relying on legitimate cloud services and adaptive communication methods to make malicious traffic appear like normal network activity. Kaspersky said the most significant discovery is a sophisticated command and control module that uses DNS A record responses to decide whether communications should be sent directly over HTTPS or routed through Google Apps Script. The same DNS infrastructure can also validate and replace the Google Apps Script deployment identifier, allowing operators to rotate communication channels without disrupting their operations.

Cavern was first publicly documented by Check Point Research in July 2026 and is designed as a modular post exploitation framework consisting of an agent and multiple specialized modules that can be deployed depending on the attack objective. The toolkit enables attackers to carry out file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute force attacks, network reconnaissance, SOCKS5 proxy services, and WebSocket tunneling while maintaining persistence and reducing forensic visibility. Researchers have linked the framework to Cavern Manticore, a hacking group associated with Iran Ministry of Intelligence and Security, which shares operational similarities with MuddyWater and the OilRig subgroup Lyceum. Earlier reports from Group IB and Kaspersky also described another Cavern module known as HOLLOWGRAPH, which converts Microsoft 365 calendars into covert command and control channels. The malware abuses Microsoft Graph API by storing attacker commands inside calendar events and exfiltrating stolen files through encrypted attachments added to future dated calendar entries. To avoid attracting attention from mailbox owners, every malicious event is reportedly scheduled for May 13, 2050. At the same time, the malware uses DNS tunneling to refresh Microsoft Entra ID credentials required for Graph API authentication, storing updated values in a local text file. Researchers said the HOLLOWGRAPH component, compiled as a .NET NativeAOT DLL, was first detected in the wild on June 7, 2026.

Kaspersky believes Cavern transitioned to a modular plugin based architecture in late April 2026 and has linked it to OilRig, also known as APT34, with low confidence because there is no direct code reuse or infrastructure overlap. However, the company identified several operational similarities, including the use of Microsoft hosted services for command and control communications, secondary recovery mechanisms for obtaining replacement OAuth refresh tokens, and the use of compromised infrastructure located within targeted regions. The latest analysis also identified a new communication module named GoogleService.dll that reads configuration data from a local file called conf.json before performing DNS A record queries to determine whether communication should occur directly over HTTPS or through a Google Apps Script relay. When the relay option is selected, requests are first sent to the Google Apps Script deployment, which forwards them to attacker controlled infrastructure. If direct HTTPS is selected, the malware communicates with the configured server without using the relay. Researchers also discovered another component called rnp.dll that acts as an internal broker by loading framework modules, routing messages between them, and supporting runtime upgrades. Kaspersky noted that one of the primary domains associated with the activity, studiotikva.com, was originally registered in February 2024, expired in February 2026, and was registered again three months later, indicating continued development of the infrastructure.

The latest findings also coincide with a separate report from DarkAtlas describing renewed activity by Iranian hacking group APT42, which has been using the TAMECAT malware framework in spear phishing campaigns targeting individuals connected to the nuclear energy sector during April and May 2026. According to the report, attackers distributed LNK files disguised as PDF documents while using podcast and interview invitations as social engineering themes to establish credibility before delivering malware. Once executed, TAMECAT provides extensive surveillance capabilities including system enumeration, discovery, arbitrary command execution, browser credential and cookie theft, Outlook mailbox collection, screenshot capture, and multiple command and control and data exfiltration methods. DarkAtlas further reported that APT42 has incorporated generative artificial intelligence into its operations to accelerate malware development, research exploitation techniques, perform language translation, identify official email addresses, and gather intelligence on targeted organizations and individuals. Kaspersky believes the continued expansion of the Cavern framework and its growing reliance on trusted cloud services such as Microsoft 365 and Google Apps Script makes network based detection increasingly difficult because malicious traffic blends with legitimate enterprise communications.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment