# Kaspersky details Cavern malware module using DNS and Google Apps Script

_Monday, August 17, 2026 at 1:41 PM EDT · Security · Latest · Tier 2 — Notable_

![Kaspersky details Cavern malware module using DNS and Google Apps Script — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu-MyaPNuRr2_NJ_TMqLf7OYW5AzCqgHpQ6HMfxlc-qsMzwSkfWlZDbHfecZ3IRp639FVDelhMZgpbnN87Fdchoh-g08R-cAiXxr7RvfdGy_ihvMxg152HK-rbOTIOnEueRTnPT-wU0eID3vplpIN1GBClvJC5e0egCGpDb_H0ykwH1x6a4zOvpW8V-Ssy/s1700-e365/google.jpg)

Kaspersky reported that the Cavern command-and-control framework used in attacks targeting entities in Israel has added a module that uses DNS A-record responses to choose direct HTTPS or a Google Apps Script relay for each transaction.

The vendor said the DNS infrastructure can also validate and replace the relay deployment ID. Cavern's modules support post-exploitation functions including reconnaissance, file operations and tunneling. Kaspersky linked the framework to OilRig with low confidence and said the activity has been associated with Iranian state-linked hackers.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html)

---
Canonical: https://techandbusiness.org/newswire/48-EC5AuPHgNvLGGyoyalf
Retrieved: 2026-08-17T21:52:18.487Z
Publisher: Tech & Business (techandbusiness.org)
