Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Project CAV3RN is a modular espionage malware framework targeting entities in Israel. It uses advanced command and control (C2) techniques, including DNS A-record responses to dynamically switch between direct HTTPS communication and a Google Apps Script relay for each transaction. The framework leverages DNS infrastructure to validate and rotate Google Apps Script deployment IDs. It includes a local broker component that loads DLL modules, routes messages, and supports runtime upgrades. This abuse of legitimate services complicates network detection and enhances operational flexibility.
AI Analysis
Technical Summary
Project CAV3RN is a sophisticated modular espionage framework targeting Israeli entities. It features advanced C2 capabilities that dynamically select between direct HTTPS and Google Apps Script relay channels based on DNS A-record responses. The framework uses DNS infrastructure to validate and rotate Google Apps Script deployment IDs, enabling stealthy communication. A local broker component manages DLL modules, inter-component messaging, and runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay forwarding requests to actor-controlled infrastructure. This approach leverages legitimate cloud services to evade detection and maintain operational flexibility.
Potential Impact
The framework enables persistent espionage operations with stealthy and flexible command and control channels, complicating detection by abusing legitimate services such as Google Apps Script. This can lead to unauthorized data access and exfiltration from targeted Israeli entities. The modular architecture allows runtime upgrades and dynamic communication channel selection, increasing the threat's adaptability and resilience.
Mitigation Recommendations
No official patch or remediation is available as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the provided IP addresses, domains, URLs, and file hashes associated with Project CAV3RN. Network defenders should be aware of DNS-based C2 techniques and abuse of Google Apps Script for relay communications. Employing threat intelligence feeds and endpoint detection for the identified DLL components and network indicators can aid in detection and response.
Affected Countries
Israel
Indicators of Compromise
- ip: 12.19.29.30
- ip: 12.121.234.120
- domain: studiotikva.com
- domain: api.studiotikva.com
- domain: ns1.studiotikva.com
- domain: ns2.studiotikva.com
- url: https://api.studiotikva.com/api/v1/update/check
- url: https://api.studiotikva.com/ac
- hash: 904784c9943d019da332bea2cd03996f
- hash: f9156d42410c8a5429dec43329bd72e0
- hash: 2dcd4a8ac166404977cd3c48418a8cd9
- hash: 981c7404d31b8ce35ec88a6b290f354d
- hash: 34d50eec364d920b8b5d885c9bc98607
- ip: 74.65.75.102
- domain: m.studiotikva.com
- domain: p.studiotikva.com
- domain: q.studiotikva.com
- domain: ycz2.41414141303030.m.studiotikva.com
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Description
Project CAV3RN is a modular espionage malware framework targeting entities in Israel. It uses advanced command and control (C2) techniques, including DNS A-record responses to dynamically switch between direct HTTPS communication and a Google Apps Script relay for each transaction. The framework leverages DNS infrastructure to validate and rotate Google Apps Script deployment IDs. It includes a local broker component that loads DLL modules, routes messages, and supports runtime upgrades. This abuse of legitimate services complicates network detection and enhances operational flexibility.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Project CAV3RN is a sophisticated modular espionage framework targeting Israeli entities. It features advanced C2 capabilities that dynamically select between direct HTTPS and Google Apps Script relay channels based on DNS A-record responses. The framework uses DNS infrastructure to validate and rotate Google Apps Script deployment IDs, enabling stealthy communication. A local broker component manages DLL modules, inter-component messaging, and runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay forwarding requests to actor-controlled infrastructure. This approach leverages legitimate cloud services to evade detection and maintain operational flexibility.
Potential Impact
The framework enables persistent espionage operations with stealthy and flexible command and control channels, complicating detection by abusing legitimate services such as Google Apps Script. This can lead to unauthorized data access and exfiltration from targeted Israeli entities. The modular architecture allows runtime upgrades and dynamic communication channel selection, increasing the threat's adaptability and resilience.
Defensive Guidance
No official patch or remediation is available as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the provided IP addresses, domains, URLs, and file hashes associated with Project CAV3RN. Network defenders should be aware of DNS-based C2 techniques and abuse of Google Apps Script for relay communications. Employing threat intelligence feeds and endpoint detection for the identified DLL components and network indicators can aid in detection and response.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/project-cav3rn-continues/120991"]
- Adversary
- null
- Pulse Id
- 6a7b022f15eb07ffe06f79e1
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip12.19.29.30 | — | |
ip12.121.234.120 | — | |
ip74.65.75.102 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainstudiotikva.com | — | |
domainapi.studiotikva.com | — | |
domainns1.studiotikva.com | — | |
domainns2.studiotikva.com | — | |
domainm.studiotikva.com | — | |
domainp.studiotikva.com | — | |
domainq.studiotikva.com | — | |
domainycz2.41414141303030.m.studiotikva.com | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.studiotikva.com/api/v1/update/check | — | |
urlhttps://api.studiotikva.com/ac | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash904784c9943d019da332bea2cd03996f | — | |
hashf9156d42410c8a5429dec43329bd72e0 | — | |
hash2dcd4a8ac166404977cd3c48418a8cd9 | — | |
hash981c7404d31b8ce35ec88a6b290f354d | — | |
hash34d50eec364d920b8b5d885c9bc98607 | — |
Threat ID: 6a7b3f17bf8831d539f29cd8
Added to database: 08/11/2026, 15:26:15 UTC
Last enriched: 08/11/2026, 15:49:09 UTC
Last updated: 08/12/2026, 00:31:52 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.