Skip to main content
Back to Newswire
Security

Kaspersky details Cavern malware module using DNS and Google Apps Script

Kaspersky details Cavern malware module using DNS and Google Apps Script Image: Primary
Kaspersky reported that the Cavern command-and-control framework used in attacks targeting entities in Israel has added a module that uses DNS A-record responses to choose direct HTTPS or a Google Apps Script relay for each transaction. The vendor said the DNS infrastructure can also validate and replace the relay deployment ID. Cavern's modules support post-exploitation functions including reconnaissance, file operations and tunneling. Kaspersky linked the framework to OilRig with low confidence and said the activity has been associated with Iranian state-linked hackers.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire