Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
What Happened — Iranian‑linked “Cavern” (aka Cav3rn) command‑and‑control framework has added new components that route traffic through DNS tunneling and Google Apps Script. By piggy‑backing on legitimate Google Workspace traffic, the C2 traffic evades typical network‑based detections. Researchers observed the activity targeting multiple Israeli entities since December 2025.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how legitimate SaaS channels can be weaponized, creating a control gap that SOC 2 continuous‑compliance programs must monitor.
- Highlights the need for auditable logging of outbound DNS queries and third‑party cloud service usage to satisfy CC6.1 (System Operations) and CC7.2 (Vendor Management) controls.
- Directly aligns with Verisq’s Control Mapping capability, which automates evidence collection for such traffic‑monitoring controls.
Who Is Affected – Technology & SaaS providers, financial services firms, and government agencies that rely on Google Workspace or other cloud‑based collaboration tools.
Recommended Actions – Map outbound DNS and Google Apps Script usage to SOC 2 CC6.1 controls; enable DNS query logging and SaaS activity monitoring; integrate third‑party service usage into continuous compliance dashboards.
Technical Notes – The C2 leverages DNS tunneling (a classic covert channel) and Google Apps Script (a server‑side scripting environment) to blend with normal traffic. No specific CVE is cited; the technique exploits legitimate service functionality. Source: The Hacker News