Cavern Lets Operators Swap C2 Channels on the Fly

Kaspersky says the Cavern command-and-control framework now uses DNS A-record responses to choose, transaction by transaction, between direct HTTPS and a Google Apps Script relay in Iranian-linked attacks targeting entities in Israel. The same infrastructure can also validate and replace the relay deployment ID, so the operator can rotate the Google channel without changing the implant. In plain terms, the malware asks DNS which path to use, then sends commands either straight over HTTPS or through a Google-hosted relay. That makes one blocked relay or domain less useful, because the channel choice can change dynamically while the C2 stays the same. For defenders watching Google Workspace and DNS telemetry, the important part is the decoupling: takedown now has to catch a moving relay choice, not just a fixed server. The exposure sits in the command path itself, so environments that already allow Google-hosted traffic may see Cavern’s control traffic blend into normal lookups and web requests.

Sources