Skip to content
Auto-CTI
Back to today
NEW CAV3RN CRITICAL B3

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

B Securelist ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

CAV3RN exploits Google Apps Script and DNS-based channels for C2 communication, demonstrating how modern APT groups abuse legitimate cloud services to obfuscate threat activity.

Description

Project CAV3RN is an advanced malware campaign leveraging Google Apps Script as a relay for command-and-control communication and DNS-based channels for channel selection. The architecture employs a modular broker approach managing DLL components, scanning host directories at initialization. The mechanism enables multiple fallback communication paths via Google Apps Script and direct HTTPS connections, increasing C2 infrastructure resilience. The technique is particularly notable as it exploits implicit trust in Google services, complicating detection through standard network monitoring.

Risk score

75
strategic relevance
0.75

Path: strategic

ESC