Project CAV3RN is a sophisticated modular espionage framework targeting entities in Israel. Recent analysis uncovered advanced C2 capabilities using DNS A-record responses to dynamically select between direct HTTPS and Google Apps Script relay channels for each transaction. The framework employs DNS infrastructure to validate and rotate Google Apps Script deployment IDs. A local broker component discovers and loads DLL modules, routes inter-component messages, and supports runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay that forwards requests to actor-controlled infrastructure. The framework demonstrates increasing sophistication through legitimate service abuse, making network detection difficult while maintaining operational flexibility through modular architecture.
Created: 2026-08-11
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。