Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

0
Medium
Published: 08/11/2026 (08/11/2026, 11:06:23 UTC)
Source: AlienVault OTX General

Description

Project CAV3RN is a modular espionage malware framework targeting entities in Israel. It uses advanced command and control (C2) techniques, including DNS A-record responses to dynamically switch between direct HTTPS communication and a Google Apps Script relay for each transaction. The framework leverages DNS infrastructure to validate and rotate Google Apps Script deployment IDs. It includes a local broker component that loads DLL modules, routes messages, and supports runtime upgrades. This abuse of legitimate services complicates network detection and enhances operational flexibility.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 15:49:09 UTC

Technical Analysis

Project CAV3RN is a sophisticated modular espionage framework targeting Israeli entities. It features advanced C2 capabilities that dynamically select between direct HTTPS and Google Apps Script relay channels based on DNS A-record responses. The framework uses DNS infrastructure to validate and rotate Google Apps Script deployment IDs, enabling stealthy communication. A local broker component manages DLL modules, inter-component messaging, and runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay forwarding requests to actor-controlled infrastructure. This approach leverages legitimate cloud services to evade detection and maintain operational flexibility.

Potential Impact

The framework enables persistent espionage operations with stealthy and flexible command and control channels, complicating detection by abusing legitimate services such as Google Apps Script. This can lead to unauthorized data access and exfiltration from targeted Israeli entities. The modular architecture allows runtime upgrades and dynamic communication channel selection, increasing the threat's adaptability and resilience.

Defensive Guidance

No official patch or remediation is available as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the provided IP addresses, domains, URLs, and file hashes associated with Project CAV3RN. Network defenders should be aware of DNS-based C2 techniques and abuse of Google Apps Script for relay communications. Employing threat intelligence feeds and endpoint detection for the identified DLL components and network indicators can aid in detection and response.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/project-cav3rn-continues/120991"]
Adversary
null
Pulse Id
6a7b022f15eb07ffe06f79e1
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip12.19.29.30
ip12.121.234.120
ip74.65.75.102

Domain

ValueDescriptionCopy
domainstudiotikva.com
domainapi.studiotikva.com
domainns1.studiotikva.com
domainns2.studiotikva.com
domainm.studiotikva.com
domainp.studiotikva.com
domainq.studiotikva.com
domainycz2.41414141303030.m.studiotikva.com

Url

ValueDescriptionCopy
urlhttps://api.studiotikva.com/api/v1/update/check
urlhttps://api.studiotikva.com/ac

Hash

ValueDescriptionCopy
hash904784c9943d019da332bea2cd03996f
hashf9156d42410c8a5429dec43329bd72e0
hash2dcd4a8ac166404977cd3c48418a8cd9
hash981c7404d31b8ce35ec88a6b290f354d
hash34d50eec364d920b8b5d885c9bc98607

Threat ID: 6a7b3f17bf8831d539f29cd8

Added to database: 08/11/2026, 15:26:15 UTC

Last enriched: 08/11/2026, 15:49:09 UTC

Last updated: 08/12/2026, 00:31:52 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses