Cybersecurity researchers have uncovered advancements in the Cavern (also known as Cav3rn) command-and-control (C2) framework, utilized by Iranian state-sponsored hackers to target organizations in Israel. Ongoing surveillance since December 2025 has revealed new components that enhance the framework’s communication methods.
A significant discovery is a sophisticated C2 module that employs DNS A-record responses to dynamically select between direct HTTPS connections and Google Apps Script relays for each transaction. This approach allows operators to rotate the Google channel by validating and replacing the relay deployment ID through the same DNS infrastructure.
Initially documented in July 2026, Cavern comprises multiple components, including an Agent and various modules, designed to provide specific post-exploitation capabilities while minimizing forensic traces and maintaining persistent access. These modules support functions such as file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling.
The use of Cavern C2 has been attributed to Cavern Manticore, a hacking group linked to Iran’s Ministry of Intelligence and Security (MOIS), sharing similarities with groups like MuddyWater and Lyceum.
Further analysis has identified another module named HOLLOWGRAPH, which exploits Microsoft 365 calendars as covert C2 channels. This malware leverages the Microsoft Graph API to exfiltrate files and receive commands via calendar events, dating them far into the future (e.g., May 13, 2050) to avoid detection. Additionally, it uses DNS tunneling to refresh credentials for C2 communication.
The transition to a modular, plugin-based architecture in Cavern is believed to have occurred in late April 2026. This evolution aligns with tactics observed in other Iranian-linked cyber operations, such as the use of Microsoft-hosted services for C2 and the implementation of secondary recovery mechanisms for OAuth refresh tokens.
These developments underscore the increasing sophistication of state-sponsored cyber threats. The integration of legitimate services like Google Apps Script and Microsoft 365 into C2 frameworks highlights the challenges in detecting and mitigating such attacks. Organizations must enhance their monitoring capabilities and adopt advanced threat detection strategies to counter these evolving threats.