Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
AI Analysis
Technical Summary
Project CAV3RN is a sophisticated modular espionage framework targeting Israeli entities. It features advanced C2 capabilities that dynamically select between direct HTTPS and Google Apps Script relay channels based on DNS A-record responses. The framework uses DNS infrastructure to validate and rotate Google Apps Script deployment IDs, enabling stealthy communication. A local broker component manages DLL modules, inter-component messaging, and runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay forwarding requests to actor-controlled infrastructure. This approach leverages legitimate cloud services to evade detection and maintain operational flexibility.
Potential Impact
The framework enables persistent espionage operations with stealthy and flexible command and control channels, complicating detection by abusing legitimate services such as Google Apps Script. This can lead to unauthorized data access and exfiltration from targeted Israeli entities. The modular architecture allows runtime upgrades and dynamic communication channel selection, increasing the threat's adaptability and resilience.
Mitigation Recommendations
No official patch or remediation is available as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the provided IP addresses, domains, URLs, and file hashes associated with Project CAV3RN. Network defenders should be aware of DNS-based C2 techniques and abuse of Google Apps Script for relay communications. Employing threat intelligence feeds and endpoint detection for the identified DLL components and network indicators can aid in detection and response.
Affected Countries
Israel
Indicators of Compromise
- ip: 12.19.29.30
- ip: 12.121.234.120
- domain: studiotikva.com
- domain: api.studiotikva.com
- domain: ns1.studiotikva.com
- domain: ns2.studiotikva.com
- url: https://api.studiotikva.com/api/v1/update/check
- url: https://api.studiotikva.com/ac
- hash: 904784c9943d019da332bea2cd03996f
- hash: f9156d42410c8a5429dec43329bd72e0
- hash: 2dcd4a8ac166404977cd3c48418a8cd9
- hash: 981c7404d31b8ce35ec88a6b290f354d
- hash: 34d50eec364d920b8b5d885c9bc98607
- ip: 74.65.75.102
- domain: m.studiotikva.com
- domain: p.studiotikva.com
- domain: q.studiotikva.com
- domain: ycz2.41414141303030.m.studiotikva.com
- hash: c55cf5029b8cccb179472fa1d22ce2687a66c7945f79a4ec8f757451f5af9138
- hash: b43b2b28c7a3cfa6decc27cff8f5c5d5de68435a1b3417ad998b5bc545394861
- hash: da2dea79c3b6c0894ea3d2c25fb1718374091db9fdc82a58589ed4edbbd154a7
- hash: 0bb69350705ddb8104ad0ee2dadb58b4be14909220f2e7726ba448c656aca623
- hash: 218544ed5f4c322da4fbf223606f05bd66ef3ea7f8e668a0f71485a9eda1bc78
- hash: 1830b4e04981bab23b9a338edcec3002d0da1f3c
- hash: 1b14e9be18bf9e3028d08ef9b5b153e0d04150a8
- hash: 8dd86ad1ca9afbf3fb35990a9a9c691d939f1f7d
- hash: d8d44921174c48eb4b5a1469c6ce49e794f77906
- hash: e7a112dde6a9ab4c3f485889b27f7794748ea3a0
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Description
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Project CAV3RN is a sophisticated modular espionage framework targeting Israeli entities. It features advanced C2 capabilities that dynamically select between direct HTTPS and Google Apps Script relay channels based on DNS A-record responses. The framework uses DNS infrastructure to validate and rotate Google Apps Script deployment IDs, enabling stealthy communication. A local broker component manages DLL modules, inter-component messaging, and runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay forwarding requests to actor-controlled infrastructure. This approach leverages legitimate cloud services to evade detection and maintain operational flexibility.
Potential Impact
The framework enables persistent espionage operations with stealthy and flexible command and control channels, complicating detection by abusing legitimate services such as Google Apps Script. This can lead to unauthorized data access and exfiltration from targeted Israeli entities. The modular architecture allows runtime upgrades and dynamic communication channel selection, increasing the threat's adaptability and resilience.
Defensive Guidance
No official patch or remediation is available as this is a malware framework rather than a software vulnerability. Defenders should monitor for indicators of compromise such as the provided IP addresses, domains, URLs, and file hashes associated with Project CAV3RN. Network defenders should be aware of DNS-based C2 techniques and abuse of Google Apps Script for relay communications. Employing threat intelligence feeds and endpoint detection for the identified DLL components and network indicators can aid in detection and response.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/project-cav3rn-continues/120991"]
- Pulse Id
- 6a7b022f15eb07ffe06f79e1
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip12.19.29.30 | — | |
ip12.121.234.120 | — | |
ip74.65.75.102 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainstudiotikva.com | — | |
domainapi.studiotikva.com | — | |
domainns1.studiotikva.com | — | |
domainns2.studiotikva.com | — | |
domainm.studiotikva.com | — | |
domainp.studiotikva.com | — | |
domainq.studiotikva.com | — | |
domainycz2.41414141303030.m.studiotikva.com | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.studiotikva.com/api/v1/update/check | — | |
urlhttps://api.studiotikva.com/ac | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash904784c9943d019da332bea2cd03996f | — | |
hashf9156d42410c8a5429dec43329bd72e0 | — | |
hash2dcd4a8ac166404977cd3c48418a8cd9 | — | |
hash981c7404d31b8ce35ec88a6b290f354d | — | |
hash34d50eec364d920b8b5d885c9bc98607 | — | |
hashc55cf5029b8cccb179472fa1d22ce2687a66c7945f79a4ec8f757451f5af9138 | — | |
hashb43b2b28c7a3cfa6decc27cff8f5c5d5de68435a1b3417ad998b5bc545394861 | — | |
hashda2dea79c3b6c0894ea3d2c25fb1718374091db9fdc82a58589ed4edbbd154a7 | — | |
hash0bb69350705ddb8104ad0ee2dadb58b4be14909220f2e7726ba448c656aca623 | — | |
hash218544ed5f4c322da4fbf223606f05bd66ef3ea7f8e668a0f71485a9eda1bc78 | — | |
hash1830b4e04981bab23b9a338edcec3002d0da1f3c | — | |
hash1b14e9be18bf9e3028d08ef9b5b153e0d04150a8 | — | |
hash8dd86ad1ca9afbf3fb35990a9a9c691d939f1f7d | — | |
hashd8d44921174c48eb4b5a1469c6ce49e794f77906 | — | |
hashe7a112dde6a9ab4c3f485889b27f7794748ea3a0 | — |
Threat ID: 6a7b3f17bf8831d539f29cd8
Added to database: 08/11/2026, 15:26:15 UTC
Last enriched: 08/11/2026, 15:49:09 UTC
Last updated: 09/24/2026, 13:49:08 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.