Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
B Securelist ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
CAV3RN exploits Google Apps Script and DNS-based channels for C2 communication, demonstrating how modern APT groups abuse legitimate cloud services to obfuscate threat activity.
Description
Project CAV3RN is an advanced malware campaign leveraging Google Apps Script as a relay for command-and-control communication and DNS-based channels for channel selection. The architecture employs a modular broker approach managing DLL components, scanning host directories at initialization. The mechanism enables multiple fallback communication paths via Google Apps Script and direct HTTPS connections, increasing C2 infrastructure resilience. The technique is particularly notable as it exploits implicit trust in Google services, complicating detection through standard network monitoring.
Risk score
- strategic relevance
- 0.75
Path: strategic