Skip to content
Auto-CTI
Back to all actors

CAV3RN

Unknown Dormant
Mentions
1
First seen
11 Aug 2026
Last seen
11 Aug 2026

Origin

Unattributed

Profile

CAV3RN is a threat actor that, according to recent reporting, uses Google Apps Script as a C2 relay and DNS-based C2 channel selection. The activities continue under the name 'Project CAV3RN'. No details on targeted sectors, regions, or countries are evident from the provided headline.

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC