
CAV3RN Hides Cyberespionage C2 Behind Google Apps Script and Lets DNS Pick the Route
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a new command-and-control (C2) design that hides traffic behind Google Apps Script. The malware uses DNS A-record responses to decide whether each request should travel through a Google relay or directly to an attacker-controlled HTTPS server. The newly identified communication component, GoogleService.dll, is […]
The post CAV3RN Hides Cyberespionage C2 Behind Google Apps Script and Lets DNS Pick the Route appeared first on Cyber Security News.