Security
Kaspersky details Cavern malware module using DNS and Google Apps Script
Image: Primary Kaspersky reported that the Cavern command-and-control framework used in attacks targeting entities in Israel has added a module that uses DNS A-record responses to choose direct HTTPS or a Google Apps Script relay for each transaction.
The vendor said the DNS infrastructure can also validate and replace the relay deployment ID. Cavern's modules support post-exploitation functions including reconnaissance, file operations and tunneling. Kaspersky linked the framework to OilRig with low confidence and said the activity has been associated with Iranian state-linked hackers.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
